The day's tech, sifted: Jul 28, 2026

Tue, Jul 28

What matters today: An AI Forensics audit found Hugging Face hosting AI image tools that strip clothes from real people's photos on request, with only 3% of the Spaces it tested carrying any output moderation, and a week-long honeypot logged 1,081 real submissions, 73% sexual, 6.7% targeting apparent minors. Dario Amodei published Anthropic's fullest rebuttal yet to the industry's open-weights debate, denying the company has ever backed a ban, even as The Information reports OpenAI and Anthropic have separately lobbied the Trump administration to force slower-moving rivals into the same compliance reviews. And a magnitude 7.1 earthquake struck Kumamoto on Japan's Kyushu island, forcing roughly 300,000 people to evacuate before a brief tsunami advisory was lifted with no wave observed.

AI / LLMs

Devtools & Infra

Security & Privacy

Startups & Industry

Research

Elsewhere

Hacker News

Today's front page led with breaking news: a 7.1 earthquake near Kumamoto on Kyushu triggered evacuation orders for roughly 300,000 people, building collapses, and suspended Shinkansen service, plus a tsunami advisory lifted within two hours with no wave observed, covered above. Several of the day's heaviest threads point back to coverage elsewhere in this digest: Anthropic's open-weights position paper pulled the most comments of any story on the page (858), a new HIV vaccine's strong preclinical results and a judge's rejection of Google's DMCA takedown against a scraper also ran hot, and Microsoft's MAI-Cyber-1-Flash security model rounded out that cluster.

Among the newer material, a $500 reinforcement-learning fine-tune of a 9B open model reportedly beat frontier models on catalog review, alongside Google's "Beyond Zero" zero-trust architecture, extending BeyondCorp to per-action authorization at machine speed for AI agents, and a report that 68.4% of domains still don't enforce DMARC fourteen years on, also covered above. Workplace and culture stories drew outsized discussion: an essay on canceling the Hey email service, a Netflix employee reportedly fired after an unusually candid retreat trust exercise, and Ars Technica's account of a missing database underscore that sent an innocent man to prison for 18 months.

Threads

  • Amodei's open-weights rebuttal and the OpenAI/Anthropic joint lobbying report land the same day: both companies publicly defend openness and safety cooperation while asking Washington to force slower rivals into the compliance reviews they'd rather not face alone.
  • Microsoft's new security-model launch, Google's Beyond Zero agent-authorization architecture, and GitHub's supply chain hardening post are three defensive moves at three different layers the same day, while the NVD's climbing CVE tally measures how far ahead of patching the attackers still are.
  • Hugging Face's near-zero moderation of nudify models (3% of audited Spaces) lands the same day Cyera pays $1B for non-human identity security and Google ships a machine-speed agent-authorization architecture: the industry is hardening AI agents' access to enterprise systems while a much more direct harm, sexualized deepfakes of real people including minors, goes almost entirely unpoliced on a platform the same industry relies on.
  • Korean chip stocks cratering and Corning's guidance cut pull against Verizon's dark-fiber deal and Core Scientific's AMD megawatt deal: investors souring on AI-linked chip and connectivity demand even as telecoms and cloud providers keep signing multi-billion-dollar infrastructure bets.
  • Google's DMCA scraping loss and Texas's SCOPE Act loss are both courts trimming back attempts to use legal leverage to control the open web, one aimed at scrapers, one at speech.