Business, Deals & Funding
Ars Technica AI

Terabytes of credentials leaked in massive supply-chain attack
A massive supply-chain attack on LiteLLM, an open source AI development tool, exposed terabytes of credentials from over 2,500 organizations including Microsoft, Amazon, Nvidia, Samsung, Cisco, and Salesforce. The attack, attributed to the teenage hacker gang TeamPCP, compromised LiteLLM packages on the Python Package Index during a 40-minute window in March, during which malicious code scraped memory contents and exfiltrated credentials. The attack chain originated from a prior compromise of the vulnerability scanner Trivy, and also affected KICS and the Telnyx Python SDK. Security firms CloudSEK and Hudson Rock reported that approximately 434,000 CI/CD pipelines had credentials exposed, including cloud keys, SSH keys, Kubernetes secrets, and API tokens for platforms like Salesforce, Slack, and Microsoft Azure.
Why it matters
This incident is a stark illustration of the compounding risks in modern software supply chains, particularly as organizations rush to adopt AI tooling without adequate security scrutiny. The fact that a teenage hacker group could compromise widely-used developer tools and exfiltrate terabytes of secrets from major corporations in a 40-minute window is deeply alarming. It highlights several systemic failures: the lack of integrity verification for packages pulled from public repositories, the d…
Claude Code Changelog
v2.1.229
Version 2.1.229 of Claude Code introduces documentation for the `claude remote-control --continue` command to resume Remote Control sessions, adds server-supplied hook support for self-hosted runner sessions, implements SSE keepalive pings to prevent idle-timeout disconnects on Vertex and Bedrock, and adds a plugin marketplace feature allowing local commands to specify plugin directories that are re-resolved each session.
Why it matters
This release focuses on infrastructure reliability and extensibility improvements. The SSE keepalive pings addressing idle-timeout disconnects on Vertex and Bedrock is a practical fix for a real pain point during long thinking pauses. The plugin marketplace command sources feature adds useful flexibility for IDE integrations. Overall, it's a solid incremental update with meaningful quality-of-life improvements, though the changelog entry appears truncated which makes full assessment difficult.
DeepMind Blog
Putting sign language AI into users’ hands
Google DeepMind introduces sign-language-to-text (SL2T), a breakthrough AI model designed to power new sign language features for Deaf and hard of hearing users. The blog post highlights how AI advances in spoken language processing—such as translation, dictation, and conversational interfaces—have largely bypassed the sign language community, and SL2T aims to bridge that gap by enabling automatic recognition and translation of sign language into text.
Why it matters
This appears to be a genuinely meaningful application of AI technology, addressing a significant accessibility gap for Deaf and hard of hearing communities. While the blog post content is truncated and lacks technical details about the model's accuracy, supported sign languages, or limitations, the initiative itself is commendable. Sign language recognition is an extremely challenging problem due to the spatial, temporal, and grammatical complexity of sign languages, so a breakthrough here woul…
Guardian AI

Taiwan says it was hit by ‘abnormal’ AI-assisted cyber-attack
Taiwan's Ministry of Digital Affairs reported detecting AI-assisted cyber-attacks targeting government agencies from overseas, beginning on July 20. The attacks are described as 'abnormal' and represent a 'first-of-a-kind breach,' with reports linking the suspected hackers to China. The announcement came a day after initial reports of the unprecedented AI-assisted intrusion.
Why it matters
This report highlights a significant and concerning evolution in cyber warfare, where AI is now being actively weaponized to conduct sophisticated attacks against government infrastructure. The involvement of state-linked actors using AI tools to breach defenses raises the stakes considerably for global cybersecurity. Taiwan, given its geopolitical position, is a frequent target, and this development suggests that defensive cybersecurity strategies must urgently adapt to counter AI-enhanced thr…
MIT Tech Review AI

Scaling AI agents with trustworthy data
This MIT Technology Review report, produced in partnership with Google Cloud and based on a survey of 300 data and technology executives, examines how legacy data systems are limiting the effectiveness of AI agents in enterprises. Key findings reveal that AI agents currently access only an average of 45% of company data, and only about half of organizations trust their agents' decisions. A small group of 'data leaders' who provide agents access to over 70% of their data report 100% trust in agent decisions and far fewer scaling constraints. Two-thirds of 'data laggards' say legacy systems limit agent scaling and speed, compared to just 8% of leaders. All respondents plan to use agentic AI within two years, with 69% expecting wide deployment. Top priorities include improving access to structured and unstructured data, enhancing data governance with business context, and automating data m…
Why it matters
This is essentially a sponsored content piece by Google Cloud dressed up as research journalism, which should be noted when evaluating its claims. That said, the core argument is sound and unsurprising: AI agents are only as good as the data they can access, and legacy infrastructure creates real bottlenecks. The finding that 'data leaders' report 100% trust in agent decisions feels suspiciously clean and likely reflects self-selection bias—organizations that invested heavily in data modernizat…
TechCrunch AI

Some Claude users are mad that Anthropic’s new watermarks will catch them using it at their jobs, classes
Anthropic has implemented invisible watermarks in Claude's text outputs to comply with the EU AI Act's Transparency Code, which requires AI-generated content to be identifiably labeled. Some users have taken to Reddit to express anger, arguing the watermarks will expose students, journalists, and professionals who use Claude in their work. Critics claim the watermarks are 'unethical' and 'draconian,' with one arguing that since they provided the instructions and refinements, Claude was merely a tool. However, many other Reddit users pushed back, noting that the complainers are essentially upset about being caught passing off AI-generated work as their own. Some critics made more nuanced arguments, pointing out the irony of watermarking AI outputs when the models themselves were trained on other people's work without similar attribution.
Why it matters
This article highlights a genuinely interesting tension, but the core complaints from upset users are largely unconvincing. The examples cited — students copying AI-reorganized paragraphs into essays, or journalists pasting AI summaries verbatim — are precisely the kinds of uses where transparency is warranted. The article rightly points out that if a watermark only catches you when you're copying AI output directly, then the watermark is functioning as intended. The more compelling criticism i…
The Rundown AI

Anthropic slips an invisible signature into Claude
Anthropic has announced plans to embed invisible watermarks in all text, code, and file outputs from Claude models, implementing EU AI Act transparency requirements globally. Text and code will carry hidden watermarks that persist when copied, while files will use the C2PA provenance standard. Models shipping after August 2 will have watermarking built in, and older models will be retrofitted. Anthropic plans to release its own detection tools and notes that watermarks indicate content was 'processed by Claude,' not necessarily fully authored. The move has been polarizing, with reactions ranging from supportive to concerns about overreach, and other major AI companies like OpenAI, Google, and Meta are expected to implement similar measures under the AI Act, with xAI notably absent.
Why it matters
This is a significant and somewhat concerning development. While transparency about AI-generated content is a legitimate goal, embedding invisible watermarks in all outputs raises real privacy and practical concerns. Users who employ Claude as a writing assistant or coding tool may not want their work permanently tagged as AI-processed, especially since the watermark persists when copied. The distinction between 'processed by' and 'authored by' is important but likely to be lost in practice — a…
The Verge AI

Twitch streamers can now opt out from training Amazon’s AI
Twitch has introduced a new opt-out toggle that allows users to prevent their content—including streams, VODs, clips, chat messages, and channel text/images—from being used to train Amazon's generative AI models. The toggle is found in Twitch's Security and Privacy settings and appears to be enabled by default, meaning content is used for AI training unless users actively opt out. Opting out does not affect other AI-supported features like captions, safety tools, recommendations, or monetization assistance. Notably, chat messages in another streamer's channel are governed by that streamer's opt-out preferences, not the individual chatter's.
Why it matters
While it's positive that Twitch is offering an opt-out mechanism, the fact that it defaults to opted-in is a significant concern and follows a frustratingly common pattern in tech. Most users will never find or toggle this setting, effectively giving Amazon access to vast amounts of creator content by default. The distinction between generative AI training and other 'AI-supported' features also feels like a way to maintain broad data usage rights while appearing to give users control. A more et…
Guardian AI

San Francisco-area estate sells for $70m in sign of AI-fueled wealth explosion
A luxury estate in Hillsborough, south of San Francisco, sold for a record $70 million to a buyer reportedly involved in the AI industry. The sale, described as Lake Como-inspired, doubles the previous record for the affluent town and reflects a new wave of AI-fueled tech wealth driving extraordinary home prices in the San Francisco Bay Area. The transaction signals the emergence of a new class of AI multimillionaires entering the high-end real estate market.
Why it matters
This sale is a striking indicator of how rapidly AI industry wealth is concentrating and manifesting in tangible assets. While it's not surprising that a new tech boom produces extravagant real estate purchases — we saw similar patterns during previous Silicon Valley cycles — the scale and speed are notable. A $70 million residential sale in Hillsborough, doubling the previous record, suggests AI wealth is already rivaling or exceeding the fortunes generated by earlier tech waves. This raises b…
TechCrunch AI

Amazon will train on Twitch streamers’ content by default, unless they opt out
Twitch, owned by Amazon, has updated its policies to allow creators' content to be used for training Amazon's generative AI models by default, requiring streamers to manually opt out. Twitch CPO Mike Minton openly admitted the reason for the opt-out rather than opt-in approach: 'If this was opt-in, nobody would opt in.' The change has sparked significant backlash from the Twitch community, which is largely opposed to generative AI training on their content. Twitch framed the announcement as adding an opt-out setting rather than announcing AI training, and Minton could not confirm whether Amazon had already used Twitch content for model training. Twitch Head of Community Mary Kish defended the move by comparing it to Meta's similar practices and characterized the opt-out option as a concession to community feedback.
Why it matters
This is a remarkably brazen move, made even more striking by Minton's candid admission that they chose opt-out precisely because they know creators don't want this. That statement is essentially saying 'we know you don't consent, so we're not going to ask.' The framing of the announcement as generously 'adding an opt-out setting' rather than honestly stating 'we're taking your content for AI training' is manipulative corporate communication at its finest. Comparing it to Meta's practices, as Ki…
The Verge AI

Guitar company D’Addario admits that AI music was used in a promotional video
Guitar string company D'Addario has admitted that AI-generated music from Suno was used in a promotional video, after nearly two weeks of denying the allegations and offering various alternative explanations. The company had previously attributed the suspicious audio to low-quality exports, Autotune artifacts, and AI-assisted mastering tools. D'Addario also faced criticism for deleting comments from critics and blocking users. The company apologized, said it does not support AI-generated music, and pledged to require disclosure of any generative AI use by employees and creative partners going forward.
Why it matters
This is a particularly damaging situation for D'Addario because they are a company that exists to serve musicians — the very people most threatened by AI-generated music. The weeks of denial and heavy-handed comment moderation made things significantly worse than if they had simply owned up immediately. It's a cautionary tale about how companies in creative industries need to be especially careful about AI use, and how cover-ups invariably compound the original offense. The fact that they quiet…
Guardian AI

Science funding and unnecessary fear | Letters
The article discusses UK Research and Innovation (UKRI) science funding cuts, highlighting concerns beyond the well-publicized closure of Jodrell Bank. Prof Stephen Blundell draws attention to the threatened world's most intense source of pulsed muons at the Rutherford Appleton Laboratory, emphasizing its scientific importance. The article also includes a letter from Peter Forbes addressing bacteriophages and AI. The letters argue that these cuts affect critical but less visible scientific infrastructure and research capabilities.
Why it matters
The article presents a critical perspective on the UK government's science funding cuts, suggesting they are short-sighted and damaging to important scientific infrastructure. The authors clearly oppose the cuts, arguing that facilities like the Rutherford Appleton Laboratory's muon source deserve the same public attention and defense as more iconic institutions like Jodrell Bank. The tone conveys frustration that vital but less publicly visible research capabilities are being sacrificed, and t…
TechCrunch AI

AI coding startup Cognition reportedly already in talks to raise at $40B valuation
AI coding startup Cognition, maker of the AI coding agent Devin, is reportedly in talks to raise a new funding round at a $40 billion valuation, just months after raising $1 billion at a $26 billion valuation in May 2026. The potential valuation increase is based on the company approaching a $1 billion annualized revenue run rate, up from $492 million ARR three months prior. Cognition's CEO Scott Wu has positioned Devin not as a human replacement but as a tool for handling tedious programming tasks like legacy code updates and platform migrations. The company counts Mercedes-Benz, NASA, and Goldman Sachs among its customers, with enterprises reportedly growing their Devin usage by 50% month-over-month over the past six months.
Why it matters
Cognition's trajectory is remarkable but also emblematic of the frothy AI investment environment. Doubling ARR from ~$492M to ~$1B in just a few months is genuinely impressive if accurate, and it suggests real enterprise demand rather than hype alone. The positioning of Devin as a grunt-work automation tool rather than a developer replacement is strategically smart — it reduces organizational resistance to adoption and targets high-volume, low-glamour tasks that represent real pain points. Howe…
The Verge AI
Google’s Pixel Watch 5 dives deeper into AI and health
Google announced the Pixel Watch 5 at $399, a $50 price increase over last year. Hardware changes are minimal — a new satin pyrite case finish, new strap colors, a Steph Curry Special Edition, a slightly faster Qualcomm processor, and a small battery improvement. The major updates are software-focused, including offline Gemini AI, proactive AI suggestions, improved GPS maps, and new health features like insulin resistance trend tracking. The price hike is attributed to increased RAM costs.
Why it matters
This appears to be a classic incremental smartwatch update where the hardware barely changes but the software does the heavy lifting to justify a higher price tag. The $50 price increase for what amounts to minor spec bumps and AI features that could theoretically be pushed to older models feels like a tough sell. The health features like insulin resistance trends sound genuinely useful, and offline Gemini on a watch could be compelling, but consumers may rightfully question whether these softw…
From X/Twitter
- Jason Cohen on Product Purgatory: when the customer believes, the budget exists, but you're simply not in their top three priorities.
- MCP v2 goes stateless — Ashley Peacock shows all the code you need to build a stateless MCP server on Cloudflare Workers.
- Peter Yang makes the case that we're shifting from keyboards and mice to directing agents in the cloud with our voices.
- Claire Vo says AI stalls inside companies for two reasons: people aren't creative enough to reimagine workflows, and leadership won't commit resources.
- Shannon Holmberg's framework for AI copywriting: pick the right model, codify your casing, rhythm, and lexicon as rules, and feed it examples of your published work.
- Tom Critchlow's new essay: how to keep thinking in an age that rewards reacting.
- Kevin Rose says Digg is now running 100+ agents, judges, and automated tasks two months after relaunch — traffic up 20%+ month over month on Grok models.
- Jack Cheng built disposable control panels he calls "jigs" to tune 27 variables in one animated explainer — because prompting alone can't move a headline one pixel higher.
- Alex Lieberman says his engineers at Tenex Labs are losing their minds over Amp's Orb product — parallelized work on the same codebase with live VM portals.
- Patrick Collison shares Fast Company's interviews with New Aesthetics grantees.
- Buffer is now a Claude connector — ask for your top posts, get real data back, generate drafts, and push them straight to your queue across 11 channels.
- An engineer built claudish-to-english, a plugin that translates Claude's verbose output into plain language. 2.3K Reddit upvotes say he struck a nerve.
- Jason Cohen's cold water on solo AI companies: you'll need to describe every role in excruciating detail, then manage and improve all the agents — the exact work you were trying to avoid.
- Matt Ragland worries Claude's watermark detection will become a dog whistle to dismiss ideas entirely, even when AI is just cleaning up a voice ramble.
- Claude's Chrome sessions now carry over to desktop, web, and mobile — conversations saved, skills and connectors intact. Available on Max and Team today.
From Reddit/HN/YC
- [Hacker News] The Hitchhiker's Guide to the Internet from 1992 is exactly the time capsule you think it is.
- [Hacker News] A hardware researcher launched a CPU deoptimization project to find the slowest x86 instruction — worst offender takes 198 billion cycles to execute.
- [Hacker News] Bullet (YC S26) pitches itself as a faster coding agent built for speed over chat.
- [Hacker News] Comma.ai launches Chestnut, a PCIe Gen4 x4 to USB4 dock with fully open-source firmware.
- [Hacker News] JEDEC previews the LPDDR6 roadmap with 512 GB densities and a new SOCAMM2 standard.
- [Hacker News] Relational-to-KV uses AI to map relational models to ToplingDB/RocksDB automatically.
- [Hacker News] A coin-sized device can hack a Boeing 737 — Wired has the details.
- [Hacker News] How one team used TiKV and MinIO to index hundreds of terabytes of JSON on low-memory hardware.
- [Hacker News] Self University teaches system engineering via interactive puzzles — no lectures, just broken systems to fix.
- [Hacker News] Nvidia doubles the RTX PRO 6000 Blackwell's MSRP to $16,000 — it started pre-orders below $8k last year.
- [Hacker News] China's 1,110 kg maglev model train hits 800 km/h in 5.3 seconds.