The day's tech, sifted: Aug 4, 2026
What matters today: Anthropic signed a $10 billion, six-year deal for computing capacity in Norway from Volta Infra, a months-old, Nvidia-backed AI cloud startup that also disclosed a $300M funding round the same day, routing around the exact power constraint Texas imposed hours earlier when it ordered a halt on new data center grid connections pending an audit, with 474+ GW of projects already queued. Markets kept rewarding the buildout regardless: Amazon closed above $3 trillion in market value for the first time, and Palantir and Snap both beat Q2 estimates. Security cut the other way today: a self-propagating worm compromised 1,300+ npm packages with a combined 2 billion monthly downloads, NHS England admitted Palantir engineers can access identifiable patient data, and some shared Claude conversations turned out to be searchable on Google.
AI / LLMs
- An AI-supervised remote entrance exam for UNAM, Mexico's largest university, went badly wrong for its nearly 160,000 applicants: where 3.5% of test takers scored 100 or higher between 2021 and 2025, 16.3% did this year under the lockdown-browser, AI-proctored format, and 58,000 students must retake it.
- Meta doubled the training efficiency of GEM, the generative ads recommendation foundation model behind Instagram and Facebook, to 20-25% Model FLOPs Utilization while scaling training compute 4x in 12 months, via custom attention kernels and mixed ultra-low-precision training, evidence recommendation systems, not just chatbots, are now getting LLM-scale infrastructure investment.
Devtools & Infra
- Vercel's v0 API v2 lets developers embed v0's full app-building agent, prompt, preview, iterate, deploy, directly into their own products and pipelines, shipped alongside Next.js 16.3's Instant Navigations for single-page-app responsiveness plus a faster dev server and builds and Vercel WAF for Blob reaching general availability, edge firewall rules that can deny, challenge, or rate-limit requests to stored objects before they generate a bill.
- Cloudflare shipped an entire agent platform in one day: an Agent Development Lifecycle framework structuring how teams build with AI agents, Cloudflare Wallets, a programmable wallet giving agents their own identity and payment method to sign up for APIs without a human in the loop, and Cloudflare Agents, bundling model access, durable runtime, sandboxed execution, and observability for hosted agents.
Security & Privacy
- A self-propagating worm named ChainDrop, descended from the Shai-Hulud campaign, compromised more than 1,300 npm packages including Keyv, Cacheable, and flat-cache, a combined 2 billion monthly downloads across the affected packages.
- NHS England apologised and admitted engineers from Palantir and other suppliers have access to identifiable patient data through the Federated Data Platform, contradicting its own Data Protection Impact Assessment, which claimed only NHS staff could see such data; the correction followed scrutiny from the National Data Guardian.
- Some Claude conversations shared via Anthropic's public share links turned out to be indexed and searchable on Google, exposing cryptocurrency wallet keys, home addresses, and a vibe-coded therapy app's data; Anthropic says the links aren't guessable and public content may be archived by third parties like any other public web page.
- Ukraine's SkyFall and US firm Auterion are fielding AI autonomy kits on $400 Shrike kamikaze drones, letting an operator fly manually into range, designate a target up to half a mile out, then switch to fire-and-forget autonomous terminal guidance; the companies plan to deliver 50,000 of the AI-equipped drones in the coming months.
- Apple briefly pulled Telegram from the App Store on Monday over CSAM content, restoring access about 20 minutes later after Telegram said it removed the content and banned the user.
- The Wall Street Journal reports DHS sent platforms hundreds of subpoenas and asked posters to sign letters saying speech about ICE "may" be a crime, part of a surveillance program the agency says searches for threats to its agents but critics call free-speech infringement.
- Show HN: Nightcrawler runs a fully autonomous pentesting agent entirely on a rooted Android phone, using a local 1.2B-parameter model for recon, exploitation, and reporting with no cloud connectivity, 27 exploit playbooks, and a 24,956-entry CVE database on board.
Startups & Industry
- Texas ordered its Public Utility Commission and grid operator ERCOT to audit data center connection requests before approving more, with 474+ GW of projects already queued, more than five times the grid's peak demand.
- Amazon closed above $3 trillion in market value for the first time Monday, the fifth company ever to reach the mark after Nvidia, Alphabet, Microsoft, and Apple, with its stock up 4.58% on the day.
- Palantir's Q2 revenue rose 93% year over year to $1.94B, beating estimates, with US commercial revenue up 149%, and Snap's Q2 revenue rose 19% year over year to $1.6B with daily active users up 5% to 493M, both ahead of estimates; all three companies' shares jumped after hours.
- Volta Infra, a months-old AI cloud startup backed by Nvidia, raised $300M led by a16z and Altimeter at a $2.4B valuation, the same day Bloomberg reported Anthropic agreed to a $10B, six-year deal for Volta's computing capacity in Norway, matching the "unnamed leading AI developer" behind Volta's marquee contract.
- OpenAI rebutted Apple's trade-secrets lawsuit as a "careless, aggressive and oddly personal lawsuit," saying it doesn't have or want Apple's trade secrets, the latest escalation since Apple sued last month claiming OpenAI stole hardware designs for a rival AI device.
- TikTok agreed to settle three more teen social media design-liability lawsuits ahead of trial, with 2,600 similar cases still pending in California federal court.
Research
- The first dynamic security assessment of internet-facing MCP servers audited 414 of 640 confirmed production instances and found 68 reportable vulnerabilities, including SQL injection and SSRF against cloud metadata services; 91.8% lacked OAuth authentication and 41.6% of confirmed servers disappeared within three days between measurement runs, pointing to deployment far outrunning security review.
- A new taxonomy of attack vectors for multi-agent web systems includes a "Telephone Loop" attack that exploits cross-agent delegation to trap agents in cyclical tasks, harmless against single-agent setups but compromising Claude Sonnet 4.5, GPT-5.2, and GPT-5.4 at an average 80% rate; only Claude Sonnet 4.6 resisted, catching it 92% of the time.
Hacker News
Two stories argued design choices are quietly eroding trust: a blogger's case for why AI-generated images discourage readers before they reach the text (discussion), and an Xbox outage that blocked owners from playing games they own on disc (discussion) reignited always-online DRM complaints. On the tooling side, FFmpeg shipped version 9.0, alongside two efficiency demos: an 80B-parameter Qwen running in 4.3GB of RAM on a Mac, and a 35B model on an iPhone, and DeepSeek's V4 Flash running on a single AMD MI300X.
OpenAI's "Apple is getting this wrong" post drew traffic as the two companies' trade-secrets fight escalates elsewhere in today's news (see Startups & Industry), and Lilian Weng's harness engineering for self-improvement made the front page on agent scaffolding design. A lighter thread: HN noticed Ray Bradbury's "There Will Come Soft Rains" is set on today's exact date, sending readers back to the 1950 original. NHS's Palantir data-access admission and the ChainDrop npm worm, both covered above, also topped the page.
Threads
- AI infrastructure's power problem drew three different responses today: Texas ordered a grid halt on new data center hookups, Anthropic signed a $10B deal to source computing capacity from Norway instead of the US grid, and Wall Street kept rewarding the buildout anyway, Amazon's $3 trillion close and Palantir and Snap's earnings beats landing the same day.
- Security failures spanned the AI stack: a self-propagating worm hit the software supply chain (ChainDrop, 1,300+ npm packages), a health system's own paperwork undersold how exposed patient data really was (NHS and Palantir), a sharing feature turned private AI conversations into searchable web pages (Claude and Google), and a fresh audit found most public MCP servers running with no authentication at all.
- Developer tooling caught up to the agent trend from multiple directions: Cloudflare shipped a full agent platform (build, deploy, debug, pay) in one day, Vercel pushed its own agent-building API further into production pipelines, and Meta doubled the training efficiency of an ads model that isn't a chatbot at all.
- Platforms answered for what they host from three directions at once: Apple pulled Telegram over CSAM, DHS pressured platforms over ICE-critical speech, and TikTok kept settling teen-harm suits, moderation cutting both toward and against speech on the same day.