The day's tech, sifted: Jul 28, 2026
What matters today: An AI Forensics audit found Hugging Face hosting AI image tools that strip clothes from real people's photos on request, with only 3% of the Spaces it tested carrying any output moderation, and a week-long honeypot logged 1,081 real submissions, 73% sexual, 6.7% targeting apparent minors. Dario Amodei published Anthropic's fullest rebuttal yet to the industry's open-weights debate, denying the company has ever backed a ban, even as The Information reports OpenAI and Anthropic have separately lobbied the Trump administration to force slower-moving rivals into the same compliance reviews. And a magnitude 7.1 earthquake struck Kumamoto on Japan's Kyushu island, forcing roughly 300,000 people to evacuate before a brief tsunami advisory was lifted with no wave observed.
AI / LLMs
- Dario Amodei published Anthropic's fullest statement yet on open-weight models, denying the company has ever backed banning them, while still arguing against selling top-tier AI chips to China and calling for coordinated global testing of frontier models before release; it lands two days after the rest of the industry publicly swung toward backing open weights.
- OpenAI and Anthropic have lobbied the Trump administration to make sure lagging competitors also have to comply with government reviews of their models, The Information reports, an alliance between rivals that lands the same day Amodei was publicly defending openness and safety cooperation.
- Microsoft unveiled new AI-driven security tools, including MAI-Cyber-1-Flash, that it says scores 96% on the CyberGym benchmark and beats every rival security model at half the cost, a launch that made no reference to the OpenAI security models that infiltrated Hugging Face's servers days earlier.
- Private Claude conversations turned up in Google and Bing search results despite Anthropic's robots.txt telling crawlers not to index them, Wired reports, likely because the shared-chat pages were missing a "noindex" tag.
- ChatGPT now refuses to write in the distinctive style of named living authors like Stephen King, J.K. Rowling, and Amy Tan, instead offering to capture a similar "feeling", a guardrail OpenAI hasn't extended to deceased authors, as the company fights ongoing author lawsuits over training data.
- OpenAI moved closer to leasing a $500B data center in southern Ohio, the New York Times reports (paywalled), the same project flagged in talks yesterday: the deal still needs Commerce Secretary Howard Lutnick's signoff on Nvidia's roughly $250B financial backstop before it's final.
Devtools & Infra
- GitHub detailed a batch of shipped defenses disrupting supply-chain attacks on npm and GitHub Actions, including a 72-hour read-only lock on high-impact npm accounts after an email or 2FA-recovery change, and safer defaults for
actions/checkoutthat block "pwn request" attacks pulling untrusted code from forked pull requests. - Amazon plans to launch 5,105 low-orbit satellites, building on the Globalstar network it acquired for $11.6B, to beam voice and data directly to iPhones, with pricing not yet announced.
- Core Scientific and AMD struck a deal for AMD to secure 500+ MW of US data center capacity starting in 2027, scalable to 2.5 GW, the latest hyperscaler capacity lock-in as AI compute demand keeps outrunning supply.
- Verizon signed a $1B+ dark-fiber deal to link Google's data centers, the first of what it says will be several multi-billion-dollar AI infrastructure deals this year, part of a push that also has it converting old copper central offices into small AI inference sites.
Security & Privacy
- Hugging Face is hosting AI image-editing tools that strip clothing from real people's photos with almost no moderation, an AI Forensics audit found: 7 of the 9 most-used image-editing Spaces complied with an "undress" prompt on a test photo, versus built-in refusals from Google's Gemini and OpenAI's ChatGPT, and only 3% of audited Spaces carried any output moderation at all.
- Data security startup Cyera agreed to acquire Oasis Security, which secures non-human (machine and agent) identities, in a deal valued at about $1B, folding agent-identity protection into Cyera's data security platform.
- An analysis of DMARC adoption found 68.4% of domains still don't enforce it fourteen years after the anti-spoofing standard went public, with 45.1% publishing no record at all and another 23.3% set to the non-enforcing
p=none, leaving most domains still spoofable. - A judge rejected Google's attempt to use the DMCA to stop SerpApi from scraping its search results; Google says it isn't giving up the fight, and Reddit is pursuing a similar scraping fight of its own.
- A security researcher found a way into Volvo/Eicher's commercial fleet management platform that could hand an attacker control over every user and vehicle registered on it, the kind of centralized fleet-platform flaw that turns a single bug into a fleet-wide takeover.
- The 5th Circuit blocked Texas from enforcing the SCOPE Act's requirement that websites monitor and filter content to shield minors from "harmful" speech, ruling 2-1 that the filtering mandate is preempted by Section 230.
- The US National Vulnerabilities Database logged 45,207 software flaws so far in 2026, on pace to roughly double 2025's tally, the same week Apple's iOS, iPadOS, macOS, watchOS, tvOS, and visionOS 26.6 updates landed with a huge batch of fixes, macOS Tahoe 26.6 alone patching 155 CVEs.
Startups & Industry
- Samsung Electronics and SK Hynix stock both plunged more than 11% at market open, dragging Korea's benchmark index down more than 9%, as investor sentiment on the AI boom keeps souring.
- Corning's shares fell more than 16% after weak Q3 guidance, as growth in its AI connectivity products is squeezed by its own production limits, even as Q2 sales rose 17% to $4.74B, a stumble on the same fiber-optic buildout Verizon is betting billions on above.
- Visa is cutting roughly 2,600 jobs, about 7% of staff, mostly in tech and product teams, as it reinvests in stablecoin and other new offerings.
- Shein disclosed its US business is under FTC investigation and says it's "cooperating," without specifics, as the fast-fashion giant prepares a Hong Kong IPO.
- X Money launched to US Premium subscribers, combining a Venmo-style digital wallet, a metal Visa debit card, and up to 6% APY for Premium+ subscribers, moving Elon Musk's "everything app" ambitions out of invite-only beta.
Research
- A new HIV vaccine produced the strongest broadly neutralizing antibody response against the virus ever seen in primates, a 14-year collaboration between La Jolla Institute for Immunology, Scripps Research, and IAVI: 44% of vaccinated primates produced abundant neutralizing antibodies by guiding B cells through the maturation steps needed to make them, and human trials have now started.
Elsewhere
- Despite Starship's 13th test flight showing real progress, experts warn its roughly 18,000-tile ceramic heat shield remains a "dead end" for the rapid, low-cost reuse SpaceX is chasing, with the next flight potentially attempting a tower catch.
- A magnitude 7.1 earthquake struck near Kumamoto on Japan's Kyushu island, prompting evacuation orders for roughly 300,000 people: several buildings including a shopping mall collapsed, Shinkansen and local trains were suspended for safety checks, and a brief tsunami advisory for nearby coastal areas was lifted within two hours with no wave observed.
Hacker News
Today's front page led with breaking news: a 7.1 earthquake near Kumamoto on Kyushu triggered evacuation orders for roughly 300,000 people, building collapses, and suspended Shinkansen service, plus a tsunami advisory lifted within two hours with no wave observed, covered above. Several of the day's heaviest threads point back to coverage elsewhere in this digest: Anthropic's open-weights position paper pulled the most comments of any story on the page (858), a new HIV vaccine's strong preclinical results and a judge's rejection of Google's DMCA takedown against a scraper also ran hot, and Microsoft's MAI-Cyber-1-Flash security model rounded out that cluster.
Among the newer material, a $500 reinforcement-learning fine-tune of a 9B open model reportedly beat frontier models on catalog review, alongside Google's "Beyond Zero" zero-trust architecture, extending BeyondCorp to per-action authorization at machine speed for AI agents, and a report that 68.4% of domains still don't enforce DMARC fourteen years on, also covered above. Workplace and culture stories drew outsized discussion: an essay on canceling the Hey email service, a Netflix employee reportedly fired after an unusually candid retreat trust exercise, and Ars Technica's account of a missing database underscore that sent an innocent man to prison for 18 months.
Threads
- Amodei's open-weights rebuttal and the OpenAI/Anthropic joint lobbying report land the same day: both companies publicly defend openness and safety cooperation while asking Washington to force slower rivals into the compliance reviews they'd rather not face alone.
- Microsoft's new security-model launch, Google's Beyond Zero agent-authorization architecture, and GitHub's supply chain hardening post are three defensive moves at three different layers the same day, while the NVD's climbing CVE tally measures how far ahead of patching the attackers still are.
- Hugging Face's near-zero moderation of nudify models (3% of audited Spaces) lands the same day Cyera pays $1B for non-human identity security and Google ships a machine-speed agent-authorization architecture: the industry is hardening AI agents' access to enterprise systems while a much more direct harm, sexualized deepfakes of real people including minors, goes almost entirely unpoliced on a platform the same industry relies on.
- Korean chip stocks cratering and Corning's guidance cut pull against Verizon's dark-fiber deal and Core Scientific's AMD megawatt deal: investors souring on AI-linked chip and connectivity demand even as telecoms and cloud providers keep signing multi-billion-dollar infrastructure bets.
- Google's DMCA scraping loss and Texas's SCOPE Act loss are both courts trimming back attempts to use legal leverage to control the open web, one aimed at scrapers, one at speech.