ChatGPT drops its free-plan limits, Google Assistant gets an end date, and fake 'paste this to fix it' pages come for Macs
ChatGPT is lifting the chat limit on free accounts
OpenAI is making GPT-5.6 Luna the default model for free and lower-tier ChatGPT accounts this week, and says it will remove the rate limit on text chats for those plans next week — with normal abuse protections still in place. Free accounts also get the "Think" button, which lets the model spend longer on a harder question before answering. BleepingComputer has the rundown of what is and is not included: the uncapped part is text conversation only, so file uploads, image generation and the other tools keep their existing caps. OpenAI describes the change and the accompanying model update in its own announcement, which also covers stricter content rules for accounts it believes belong to under-18s. The rollout is gradual, so the change may take a few days to reach a given account. Why it matters: if you stopped using ChatGPT because you kept hitting "you've reached your limit" partway through a task, the main reason to pay for the cheapest tier is going away. It is a good moment to re-test whether a paid plan is still earning its place in your monthly software spend — and worth remembering that free-tier conversations are the ones most likely to be used for training unless you turn that off in settings.
Google Assistant disappears from phones and watches starting September 4
Google has begun telling Assistant users that the product is being discontinued and that Gemini "is now the assistant experience on Android." Removal starts September 4 and rolls out over a few weeks across Android phones and tablets, Wear OS watches, headphones, and Android Auto projected from a phone. 9to5Google quotes the notice directly, including the part that matters most: once Assistant is removed from a device, you cannot switch back on that phone, tablet, or anything paired to it. Cars with Google built-in, TVs and smart displays keep the old Assistant for now. Ars Technica notes the switch is not optional. Why it matters: this is a forced change to something people use hands-free while driving or cooking, and the two assistants do not behave identically — voice routines, timers, alarms and smart-home commands are worth testing rather than assuming. Before September 4, open the Gemini app on your phone and run through the three or four voice commands you actually rely on. If one of them does not work the way you need it to, you have four weeks to find a replacement while Assistant is still there to compare against.
Fake "run this command to fix it" pages are now targeting Mac owners
The trick that used to end with a fake CAPTCHA and a Windows Run box has been rebuilt for macOS. Researchers tracked more than 250 lookalike domains that check a visitor's device before deciding what to show: Mac visitors get a GitHub-styled "Download for macOS" page with a forged verification badge, while everyone else sees a blank or harmless page, which is what keeps the campaign off scanners. The Hacker News describes the fingerprinting gate and the two password stealers it delivers. Victims are told to copy a scrambled command into Terminal; it pulls down a script that grabs browser-saved passwords, Apple Keychain contents, authentication tokens and crypto wallets. A related wave documented by BleepingComputer arrives by email and quietly redirects outgoing crypto transactions rather than draining a wallet all at once, which delays the moment anyone notices. Why it matters: every version of this attack needs the same thing from you — that you personally paste a command into Terminal — because nothing else on a Mac would let it in. Adopt the flat rule: no website, CAPTCHA, error message, support chat or download page ever has a legitimate reason to ask you to paste text into Terminal, and the answer is always no, including when it looks like a developer site you use. Then update to macOS 26.4 or later, which adds a confirmation prompt for exactly this behavior, and if you or anyone on your team has already run one of these commands, treat every password stored in that browser as compromised and change them from a different device.
The leading AI browsers can be hijacked by instructions hidden in an email
At the Black Hat security conference, researchers demonstrated a flaw class they call PleaseFix against the five best-known AI browser assistants: Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas and Copilot Edge. The research is published in full. The attack needs no click and no approval — hidden instructions are planted in ordinary content the assistant reads, such as an email or a calendar invite, and the assistant, which cannot reliably tell your request apart from text it encounters while working, carries them out inside your logged-in session. In the demonstrations, asking an assistant to summarize an inbox was enough to pull data out of Gmail, share an entire Google Drive with an outsider, and take over other connected accounts; Wired reports a separate case in which an AI browser was made to complete an unauthorized Amazon purchase. The findings went to all five companies before publication — some shipped patches, others said the behavior was working as designed. Why it matters: an AI assistant inside your browser inherits every account you are signed into, which is a very different risk than a chatbot in a separate tab, and the industry has not settled on a fix. If you want to use one, give it a browser profile of its own with nothing sensitive signed in — no email, banking, payroll, or customer systems — and turn off any setting that lets it act without asking. If your business already has one deployed on staff machines, that separation is worth doing this week rather than next quarter.
Shopify says AI assistants are sending shoppers to small stores, not replacing them
Shopify reported that traffic and orders reaching its merchants from AI assistants tripled year over year in the second quarter, while traditional search sessions also grew and still account for roughly a third of storefront visits. The detail most relevant to smaller sellers: 75% of AI-attributed purchases came from outside the platform's top 100 product categories, and half of AI-referred visits landed straight on a product page rather than a homepage or category page — about two and a half times the rate seen from traditional search. TechCrunch has the figures and the company's read on them. The company's framing is that shoppers describe a situation to an assistant — the seat that fits three across a sedan — where a search box only ever got the product name. Why it matters: this is one company's data about its own stores, so treat the trend as directional rather than settled. But the practical implication holds for any small catalog: buyers arriving this way skip your homepage entirely, so each product page has to answer the specific question that sent them — dimensions, compatibility, materials, what it fits and what it does not — in plain text a machine can read. Check whether your best-selling product pages actually say those things, and check your analytics for referrals from assistant domains so you can tell whether this is happening to you yet.