{"slug": "runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled", "title": "Runtime: Patch Tuesday's gone; Tencent does AI for a nickel; CoreWeave's tangled web", "summary": "Tencent researchers developed a recursive method to train AI agents on 1,000 tasks for $50, or five cents per task, dramatically cutting data curation costs. Meanwhile, CoreWeave's Q2 2026 revenue doubled but its net loss widened and debt mounted, and Microsoft's Patch Tuesday cycle is expanding as AI speeds vulnerability discovery, with mean time-to-exploit dropping from 2.3 years in 2018 to 13 hours and projected to reach 1 minute by 2027, according to the Zero Day Clock.", "body_md": "[Runtime](/tag/runtime/)\n\n*Welcome to Runtime! Today: This month's Patch Tuesday was an easier lift than last months, but patching strategies are evolving, Tencent does AI training tasks for cheap, and CoreWeave pits strong growth against a mounting pile of debt.*\n\n*Please forward this email to a friend or colleague! If it was forwarded to you, *__sign up here__* to get Runtime for free every week, or*__ level up here__*.*\n\n### First up: Patch like the wind\n\nFor almost 23 years — dating back to when dropouts Mark Zuckerberg and Sam Altman were still in college — enterprise admins have been dealing with Patch Tuesday, Microsoft's attempt to make life easier for customers by bundling potentially app-breaking security changes into a single package delivered on a single day. Over that time that approach was copied by dozens of enterprise software companies because it worked remarkably well as a way of notifying companies that they were running vulnerable software while giving them space to implement those changes at their own pace, but the times themselves are changing.\n\nModern AI security models are finding software vulnerabilities faster than ever contemplated, which has led to an explosion in the number of patches released as part of the Patch Tuesday cycle. In theory, this is a really good development, but it is forcing enterprise admins to change the way they approach the monthly ritual, as Noah Bovenizer reported.\n\n\"For the very first time, I think the risk of not patching outweighs the risk of a patch bringing down a production service,” Ivan Milenkovic, vice president of cyber risk technology for Qualys, told *The Stack*. In the olden days defenders had time to patch their systems because of how much time and expertise it took to exploit known vulnerabilities, but the [ Zero Day Clock](https://zerodayclock.com/?ref=thestack.technology) tells the story: \"the mean time-to-exploit for weaponised bugs has dropped from 2.3 years in 2018 to 13 hours, and ... will reach 1 minute in 2027.\"\n\nThe good news is that for the moment, the number of vulnerabilities that can actually be exploited still hovers in the 1% range, and modern AI tools can help admins patch their systems faster than ever. \"The human in the loop that has been the standard way of doing change management for the last 20 years is now becoming a rubber stamp in the loop,” said Gavin Millard, vice president of product at Tenable. “That introduces friction, and we haven't got time for friction anymore.”\n\n### The rest of The Stack\n\n**Nickel, backed**: AI agents are only as good as their training data, which can be expensive to assemble and curate. Researchers from Tencent, however, found a way to use recursion to train 1,000 tasks for fifty bucks, which works out to five cents per task.\n\n**Hackers, mount up**: The US government will now encourage \"vetted\" cybersecurity companies to take offensive action against hacking groups believed to have state sponsors, the Trump administration announced Wednesday. \"This is a pretty big shift in U.S. cyber policy (...) Not exactly “hack back,” but definitely a major expansion of the private sector’s role in offensive cyber operations,\" said Veracode chief security evangelist Chris Wysopal.\n\n**All you need is love**: Now that Cursor is more or less ensconced inside Elon Musk's SpaceXAI, there aren't as many independent coding agent companies as there were a few years ago. Sweden's Lovable just raised $400 million in new funding for its coding platform, which values the startup at $13.3 billion.\n\n**Double down**: No company is as intertwined with the AI boom as CoreWeave, for better or worse. During the second quarter of 2026 revenue doubled at the neocloud, but its net loss widened and it continued to pile up huge amounts of debt building out its AI infrastructure platform.\n\n**Lazarus as a service**: IBM Cloud barely even registers on [ Synergy Research's market-share ranking of cloud infrastructure companies](https://www.srgresearch.com/articles/q2-cloud-market-passes-143-billion-highest-growth-rate-in-eight-years?ref=thestack.technology) thanks to the rise of the neoclouds, but Together AI threw it a lifeline this week. Together AI will spend $240 million over the next several years to offer inference services to its own customers on top of Nvidia GPUs in IBM's arsenal.\n\n### Stack ranking: Enterprise moves\n\n**Kenny Johnston** is [ the new chief product officer at Azul](https://www.azul.com/newsroom/azul-names-kenny-johnston-chief-product-officer/?ref=thestack.technology), joining the enterprise Java company after similar roles at Luciq and GitLab.\n\n**Stuart Nash** is [ the new chief operating officer of Unit4](https://www.consultancy.uk/news/45293/unit4-hires-stuart-nash-as-chief-operating-officer?ref=thestack.technology), joining the ERP company after serving as global chief information officer of Finastra.\n\n*Enterprise Moves is back! Send your new executive announcements to tom@thestack.technology.*\n\n### We're also reading:\n\n**\"**__Stealing Reasoning Traces from Proprietary LLM APIs,__**\"** a new paper from several researchers that shows how frontier model companies are trying, and failing, to protect their models from attempts at duplicating the secret sauce.\n\n**Open models make up just 25% of AT&T's AI usage right now, but the company expects that to grow** to around 70% to 80%, [ according to The Wall Street Journal](https://www.wsj.com/cio-journal/why-at-t-is-betting-big-on-open-weight-ai-a0ea03b1?ref=thestack.technology).\n\n*Thanks for reading — see you Saturday!*", "url": "https://wpnews.pro/news/runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled", "canonical_source": "https://www.thestack.technology/runtime-patch-tuesdays-gone-tencent-does-ai-for-a-nickel-coreweaves-tangled-web/", "published_at": "2026-08-13 15:00:46+00:00", "updated_at": "2026-08-13 15:05:44.542973+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-research", "ai-infrastructure", "ai-policy"], "entities": ["Tencent", "CoreWeave", "Microsoft", "Qualys", "Tenable", "Zero Day Clock", "IBM Cloud", "Lovable"], "alternates": {"html": "https://wpnews.pro/news/runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled", "markdown": "https://wpnews.pro/news/runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled.md", "text": "https://wpnews.pro/news/runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled.txt", "jsonld": "https://wpnews.pro/news/runtime-patch-tuesday-s-gone-tencent-does-ai-for-a-nickel-coreweave-s-tangled.jsonld"}}