Independent/Reader-funded/Infrastructure, not tokens
DeAINEWS

AI you control — open models, private inference, and the networks that run them.

Open-Weights Releases

DeAI Daily Brief — 23 September 2026

Today in DeAI: 36,769 exposed self-hosted AI endpoints, a 328 GB open-weight security model, and Anthropic's GTG-16008 claim against Xiaomi.

DeAI is powered by Morpheus (mor.org). We cover competing providers on the same terms — see our methodology.

A single home-lab server cabinet with its mesh door unlatched and amber node lights glowing in a dim room, depicting the 36,769 reachable self-hosted AI endpoints from the census that leads today's brief. Illustration: DeAI
A single home-lab server cabinet with its mesh door unlatched and amber node lights glowing in a dim room, depicting the 36,769 reachable self-hosted AI endpoints from the census that leads today's brief. Illustration: DeAI

Today in DeAI: an internet-wide census finds almost no authentication in front of self-hosted AI, Aikido ships a 328 GB open-weight security model, and Anthropic's distillation allegation collides with Xiaomi's open release.

Only 2.02% of 36,769 reachable self-hosted AI endpoints return an auth challenge

Mysterium VPN researchers counted 36,769 self-hosted AI endpoints reachable and self-identifying through the Netlas scanning index, counting 18,529 Open WebUI instances, 6,935 Ollama servers answering the anonymous "Ollama is running" banner, and 4,880 vLLM endpoints, and found just 741 (2.02%) returned an HTTP authentication challenge. They contacted no host directly; this is a counted floor, not a compromise count. Why it matters: the privacy case for self-hosting holds only if nobody else can reach the box, and at internet scale almost nobody is building that perimeter. (our full coverage)

Aikido ships Altar-1: a 328 GB open-weight security model

Aikido released Altar-1 on Hugging Face: a GLM-5.3 derivative compressed from 1,506.7 GB to 328 GB via REAP expert pruning to 168 of 256 routed experts plus W4A16 quantization, sized to run on a 4×H200 node inside a customer's own perimeter. Aikido's benchmark numbers are vendor self-reports on a narrow internal CVE benchmark (Altar roughly ties its quantized parent and trails full precision), so treat 60.4% average recall as a claim, not end-to-end security performance. Why it matters: expert-pruned, quantized derivatives of frontier open models are now a practical route to domain models small enough to own; check what compression costs in fidelity before trusting the derivative.

Anthropic's GTG-16008 allegation meets Xiaomi's MiMo release

Anthropic's September threat report says Xiaomi replayed over 400,000 MiMo user conversations to Claude as training data; The Decoder's coverage sets that against the MiMo-V2.6 release from September 22. Every figure is Anthropic's own, Xiaomi has not been heard from, and the model-card figures (524B Pro, MIT) remain the verified ones. Why it matters: provenance risk is now commercial risk for anyone building on an open checkpoint. (our full coverage)

Z.ai's ZCode remedy: disablement, patch, and a retraction

Reuters reports Z.ai disabled ZCode features after the workspace-upload disclosure, named default-on "Codebase Indexing" as the root cause, patched it, and committed to a vulnerability-response process, while complainant Chengming Technology retracted its six-workspaces-uploaded allegation, citing wrong evidence. Z.ai's statement that an independent review confirmed deletion of uploaded data is unverifiable by users, because the encryption key was Z.ai's own. Why it matters: default-on indexing inside a coding agent is the failure mode; audit those defaults before pointing any agent at proprietary repositories. (context in yesterday's daily brief)

Frontier price war: Opus 5.5 and GPT-6 Sol/Luna land within an hour

OpenAI launched GPT-6 Sol and Luna at half their GPT-5.6 equivalents' prices (Luna at $0.10/M input and $0.01/M cached input, Sol at $2/M input and $10/M output), while Anthropic launched Claude Opus 5.5 at $4/M input, per Simon Willison's independent price table. All capability-parity claims are vendor benchmarks. Why it matters: cached-input pricing at $0.01/M moves the break-even point in your self-hosting-versus-API cost model more than any capability delta this week; re-run it before assuming either side wins. (context in our cost breakdown)

Watching tomorrow

Whether Xiaomi responds to GTG-16008, and whether the first post-price-cut traffic data shows builders actually re-running their cost models in the direction of cached frontier APIs.

Sources

  1. The Exposed AI Supply Chain — Mysterium VPN Research — Mysterium VPN
  2. AikidoSec/altar-1 — model card — Hugging Face
  3. Altar: open-weight AI for sovereign security — Aikido
  4. Anthropic threat intelligence report, September 2026 — Anthropic
  5. Xiaomi's affordable flagship AI leads the open models, and Anthropic says Claude helped get it there — The Decoder
  6. China's Z.ai disables AI coding assistant features after security issue — Reuters
  7. Introducing GPT-6 Sol and Luna — OpenAI
  8. Opus and Sol and Luna — price table — Simon Willison

About DeAI

DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.

Powered by Morpheus and StrandCMS

Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more about the Morpheus Inference API →

Sponsor disclosure — not editorial

Powered by Morpheus and StrandCMS. Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more →