Technology News
Daily Tech Reader - Technology Edition
Podcast 🎧 • Video 📽 • Short 📽
AI Software & Platforms
AI Software & Platforms
Anthropic Launches Theseus Infrastructure JV With Macquarie and GIC — Builds Its Own US Data Centers and Pledges to Cover Consumer Electricity Cost Increases
The joint venture gives Anthropic purpose-built US compute capacity under long-term leases without carrying construction costs on its own balance sheet, while its pledge to cover 100% of grid-upgrade costs and consumer electricity price increases is the first such commitment from a frontier AI lab.
Sources: Bloomberg · AIToolsRecap
EU DMA Orders Google to Open 11 Android Features to Claude, ChatGPT, and Copilot by August 2027 — Fines Up to 10% of Global Revenue for Non-Compliance
Binding orders issued July 16 require Google to grant rival AI assistants the same voice activation, on-device app context, and autonomous app control currently exclusive to Gemini, with Google's search data also opening to rivals from January 2027.
Sources: European Commission · AIToolsRecap
OpenAI Releases GPT-5.6-Cyber for Vetted Defenders — Specialized Model Completes 95% of Advanced Security Requests That Standard Models Refuse
The cyber-permissive model, available through a new Daybreak Red access tier requiring identity verification and legal attestation, is designed for exploit development, penetration testing, and zero-day vulnerability research on authorized systems.
Sources: VentureBeat · Axios · The Hacker News
OpenAI Delays Astra Model Release After It Reached Critical Hacking Capabilities During Safety Testing
The delay, disclosed alongside the GPT-5.6-Cyber launch, reflects the dual-use tension all frontier labs face: models powerful enough to help defenders are also powerful enough to arm attackers.
Sources: Axios
Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attacks, Anthropic Data Shows
The figure highlights how agentic coding tools are being evaluated on defensive safety metrics as they move from assisted development into autonomous execution.
Sources: IT Security News · Anthropic
AI Devices & Hardware
Google Pixel 11 Launches Tomorrow With Tensor G6 — First 2nm Smartphone Chip on TSMC Silicon, Beating Apple to the Node by Weeks
Tomorrow's Made by Google event in New York will unveil the Pixel 11 series and Pixel Watch 5, with the Tensor G6's move to TSMC's 2nm GAA process expected to address long-standing thermal throttling complaints while making Pixel the first phone line to market on that node.
Sources: 9to5Google · Android Central · Digital Trends
SAP August Patch Day: Critical CVSS 10.0 Flaw in Commerce Cloud Among 28 New Security Notes — Emergency Priority for Enterprise Teams
The maximum-severity improper authorization bug in SAP Commerce Cloud's Data Hub Adapter allows unauthenticated code injection and memory corruption, with seven additional high-severity flaws covering privilege escalation, RCE, and buffer overflow across ABAP Developer Tools and BusinessObjects.
Sources: SecurityWeek · CyberSecurityNews
AI Tool Finds 84 Flaws in 5G Network Software — 23 Remain Unpatched as Automated Vulnerability Discovery Accelerates
The finding underscores a growing gap between AI-assisted vulnerability discovery rates and the pace at which vendors can review, validate, and ship fixes for critical communications infrastructure.
Sources: IT Security News
Make UK Survey: 30% of British Manufacturers Experienced a Cyberattack in the Past Year — Major Resilience Gaps Persist Across the Sector
The survey reveals that manufacturing remains one of the most frequently targeted and least cyber-mature sectors in the UK economy, with most attacks exploiting unpatched OT systems and weak access controls.
Sources: Infosecurity Magazine · Make UK
Cybersecurity
Iran-Linked Hackers Expand US Water Infrastructure Campaign — New Jersey and Alabama Systems Hit as ICS Attacks Spread to More States
Attacks on programmable logic controllers at water utilities have now affected facilities across more than a dozen states, with threat actors rewriting PLC ladder logic to disable safety shutdowns and alarm triggers while operators countered by switching to manual field operations.
Sources: Washington Post · Fortune · TechCrunch
Red Hat Kubernetes Flaw Scores 9.9 CVSS — Low-Privilege Users Can Escalate to Cluster-Admin via Confused Deputy Attack
CVE-2026-10090 in Red Hat Advanced Cluster Management lets a user with namespace-scoped edit rights force a privileged controller to deploy attacker-controlled Helm charts cluster-wide, with no admin role required.
Sources: GBHackers · IT Security News
Valve Confirms Steam Hardware Data Breach — CEVA Logistics Shipping Partner Attack Exposed European Customer Names, Addresses, and Order Details
The attack on CEVA between July 29 and August 1 also swept up data from Dutch retailer Bol, De Bijenkorf, Ajax football club, and ING bank, illustrating how a single logistics vendor breach cascades across unrelated brands.
Sources: BleepingComputer · TechCrunch · HotHardware
DeadLock Ransomware Uses Polygon Smart Contracts to Shield Extortion Infrastructure From Takedown
By anchoring its C2 communications in blockchain transactions, DeadLock makes traditional law enforcement disruption methods — domain seizure, server takedown — significantly less effective against its extortion operations.
Sources: IT Security News
CISA Warns Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware Operators
The advisory targets internet-facing VPN appliances as the primary entry vector for Gunra, with network segmentation cited as the most effective mitigation for organizations unable to immediately apply patches.
Sources: CISA · IT Security News
Enterprise & Cloud
OpenAI Expands Daybreak Cyber Program With Two Access Tiers — Blue for General Defenders, Red for Approved Exploit Researchers
The tiered structure separates vulnerability triage and malware analysis work (Blue) from exploit chain development and red team exercises (Red), with Red requiring hardware security keys and continuous monitoring as conditions of access.
Sources: VentureBeat · BusinessToday
OpenAI, Anthropic, and Google LLM APIs Found to Expose Hidden Reasoning Traces — New Class of Vulnerability Disclosed
Researchers disclosed a vulnerability class affecting the APIs of all three major frontier AI providers, where hidden chain-of-thought reasoning traces can be accessed in ways the labs did not intend to make available externally.
Sources: IT Security News
Zoom Zero-Click Vulnerabilities Allow Meeting Participants to Hijack Other Users' Devices Without Interaction
The flaws, requiring no action from the victim, expose Zoom's meeting infrastructure to device compromise simply by sharing a virtual room with a malicious participant, raising urgent concerns for enterprise deployments.
Sources: IT Security News
Regulation & Policy
EU DMA Enforcement Sets a Global Precedent — Google Must Share Search Data With Rival AI Providers From January 2027 Under FRAND Pricing
The data-sharing order gives AI chatbot providers access to Google's query-click-ranking dataset for the first time, a significant competitive shift that could reshape how search-grounded AI responses are built across the EU market.
Sources: European Commission · AIToolsRecap
US Congress Faces Mounting Pressure to Mandate Cybersecurity Standards for Water Utilities — Current Law Has No Enforcement Teeth
The America's Water Infrastructure Act requires risk assessments but carries no financial penalties for non-compliance, and a proposed Water Risk and Resilience Organization modeled on NERC has stalled in Congress even as Iranian ICS attacks expand.
Sources: Washington Post · Fortune
White House Clinical AI Benchmarking Sprint Aims to Set Consensus Evaluation Standards for Healthcare AI Tools
The one-month sprint, run jointly by the White House and HHS, convenes outside experts to develop standardized metrics for clinical AI after stakeholders flagged the absence of consistent benchmarking as a barrier to safe deployment.
Sources: Mintz · HHS
On the Horizon
Anthropic's Infrastructure Bet Signals a New Phase — Frontier AI Labs Are Moving to Own the Physical Layer, Not Just the Model Layer
Theseus follows Microsoft's data center land rush and Google's owned-fiber strategy; the lab that controls its own compute, power contracts, and physical footprint gains a structural cost and reliability advantage that API-only competitors cannot match.
Sources: Bloomberg · AIToolsRecap
Blockchain-Backed Ransomware Infrastructure Is the Next Disruption Problem — Traditional Law Enforcement Playbooks May Not Apply
DeadLock's use of Polygon for C2 operations signals that threat actors are moving extortion infrastructure onto censorship-resistant rails, forcing a rethink of the domain-seizure and server-takedown tools that defined the last decade of ransomware disruption.
Sources: IT Security News