The models, the money, and the moves — what we read so you don't have to.
Sugata AI Weekly

Issue #004

What mattered last week in AI

The models, the money, and the moves — what we read so you don't have to.


1

Ghostcommit hides attacks in images

Security researchers unveiled Ghostcommit — a technique that hides prompt-injection payloads inside images, allowing attackers to trick AI agents into running malicious commands and exfiltrate secrets. The attack works across popular vision-language models and agentic workflows. If your agent can see, it can be tricked. Audit every image your agents process.

2

Developers misjudge AI by 39%

A METR randomized trial found experienced developers completed real coding tasks 19% slower when allowed to use AI tools. Yet they estimated afterward that AI had made them 20% faster — a 39% miscalibration between perceived and actual productivity. Trust the data, not the feeling. Measure your actual velocity before betting the farm on AI coding.

3

Slopsquatting hijacks code

Security researchers coined slopsquatting — a new software supply-chain attack where attackers publish malicious packages with names similar to AI-generated code suggestions. The goal is to trick developers into installing trojaned dependencies. The attack surface just expanded. Verify every dependency your AI coding tools suggest, not just the ones you write.

4

Microsoft backs Go for agents

Microsoft joined Google in officially supporting Go for building AI agents, citing its strong concurrency model and tooling. OpenAI and Anthropic remain focused on Python-centric agent frameworks. The battle for the agent-language throne is heating up. Go is now a first-class citizen in the agent stack.

5

GPT-5.6 lands

OpenAI released GPT-5.6 — the latest frontier model in the GPT-5 family, featuring improved reasoning, longer context windows, and enhanced tool use. The release continues OpenAI's cadence of iterative improvements. The frontier keeps advancing. If you're not on the latest model, you're leaving performance on the table.

6

Sakana's Fugu commands many models

Japanese lab Sakana AI launched Fugu Ultra — an orchestration system that presents as one model but internally routes tasks across a swappable pool of frontier LLMs, coordinating them through a single API. Sakana says it matches Anthropic's Claude Fable 5 on engineering, science, and reasoning benchmarks, and beats it on some tasks. The moat is shifting from “which model” to “who orchestrates the models.” Build for swappable backends, not a single vendor.

Building with AI?

We turn this stuff into shipped software — agents, MCP tools, automation, and apps.

See how we work →

You’re receiving this because you subscribed at sugataai.com.
Unsubscribe · © 2026 SUGATA Technology