AI
Ilya Sutskever signals SSI is ready to scale
Ilya Sutskever, who left OpenAI to found Safe Superintelligence, posted a cryptic but high-engagement message — "Time to scale that SSI" — accompanied by a link, strongly implying the secretive lab is moving into a new phase of model development or infrastructure expansion. The post drew over 9,000 likes, suggesting the AI community read it as a significant signal from one of the field's most closely watched figures.
Microsoft launches MAI-Cyber-1-Flash, its first ground-up cybersecurity AI model
Satya Nadella announced MAI-Cyber-1-Flash, Microsoft's first cybersecurity model built from the ground up to find vulnerabilities in complex codebases. Pitched as part of a broader security update offering frontier-grade protection at half the cost, the model is designed to work in combination with Microsoft's MDASH platform. The announcement marks Microsoft's first purpose-built AI model targeting the enterprise security market directly.
OpenAI expands GPT-Live voice feature to Business, Edu, and Enterprise tiers globally
OpenAI has rolled out GPT-Live in ChatGPT Voice to Education, Business, and Enterprise customers worldwide, broadening access to its real-time conversational voice capability beyond its earlier limited availability. The expansion signals OpenAI's push to embed live voice interaction into its core commercial tiers rather than keeping it a consumer-only feature.
Consumer Tech & Gadgets
Apple releases iOS 26.6, macOS 26.6, and updates across all platforms with 75+ security fixes
Apple pushed a sweeping round of software updates on Sunday, releasing iOS 26.6, iPadOS 26.6, macOS 26.6, watchOS 26.6, tvOS 26.6, and HomePod 26.6 simultaneously. The headline reason to update is security: iOS 26.6 alone patches more than 75 vulnerabilities, with Engadget noting that the broader slate of updates is primarily security-focused. Apple also issued maintenance updates for older macOS versions, shipping macOS Sonoma 14.8.8 and macOS Sequoia 15.7.8 for users not yet on the latest release.
Beyond security, the updates bring incremental new features across devices. The iOS 26.6 and iPadOS 26.6 releases carry undisclosed feature additions covered by 9to5Mac, while macOS 26.6 and watchOS 26.6 also arrive with their own changelogs. Users on legacy hardware are covered by the parallel Sonoma and Sequoia point releases.
MKBHD reviews Framework 13 Pro, the modular premium laptop
Marques Brownlee published a full video review of the Framework 13 Pro, framing it as a modular take on the premium laptop segment. The review drew strong early engagement with nearly 2,800 likes and 93 retweets, signaling significant audience interest in Framework's latest push to bring repairability and upgradability to the high-end notebook market.
Xbox suffers major outage that blocked even disc-based games from playing
Xbox experienced a widespread service outage that went beyond typical online connectivity failures, preventing users from launching even disc-based games that should work offline. Both Engadget and The Verge covered the incident, with The Verge noting the unusual severity of an outage that effectively locked players out of physical media — a scenario that highlights the growing dependency of modern consoles on always-on authentication even for local content.
Dev Tools & Infrastructure
Nuxt 4.5.1 and 3.21.10 patch multiple security vulnerabilities including a critical routeRules authorization bypass
Nuxt has released versions 4.5.1 and 3.21.10 to fix multiple security vulnerabilities, and all Nuxt users are urged to upgrade immediately. The most pressing issue is a routeRules authorization bypass that can expose protected routes even when platform-level edge rules are in place — meaning a redeploy after upgrading is required, not just a config change. A separate critical DevTools remote code execution flaw is local-development only and can be closed by running nuxt upgrade with the dedupe flag to refresh the lockfile.
Netlify added that sites still have residual exposure through public deploy previews and branch deploys, which remain vulnerable until auto-deleted — and recommended manually deleting them rather than waiting. Netlify also confirmed it patched the routeRules bypass at the platform level, but emphasized that framework-level protection still requires the user-side upgrade and redeploy.
Vercel AI Gateway adds Kimi K3, WebSocket mode for OpenAI Responses API, and Zero Data Retention support
Vercel's AI Gateway received a cluster of significant additions. Kimi K3, billed as the most powerful open-weight model currently available, is now accessible through US-based inference providers including Baseten and Fireworks AI, with Zero Data Retention agreements available for all token traffic. Separately, WebSocket mode for the OpenAI Responses API went live on the gateway, promising roughly 40 percent end-to-end latency reduction on workloads with 20 or more tool calls by keeping a persistent connection open across turns — and it runs with store=false and ZDR enabled.
GitHub Copilot rolls out prompt caching, tool search, and HyDRA auto model selection to stretch session credits
GitHub announced a set of efficiency improvements to Copilot aimed at making each session's credit allocation go further without changing how developers work. Prompt caching and a new tool search capability reduce repeated context being sent with each request, while a feature called Auto — built on an internal system named HyDRA — selects models dynamically based on the intent of the task and real-time model health. In internal evaluations, HyDRA matched the output quality of manually selected models while cutting unnecessary compute.
Gaming
Elden Ring: Tarnished Edition confirmed for Nintendo Switch 2
Nintendo of America officially announced that Elden Ring: Tarnished Edition is coming to Nintendo Switch 2, confirming the long-rumored port with a teaser post that declared "The Tarnished are coming." The edition's name suggests it will be a comprehensive package of FromSoftware's open-world RPG for the platform.
Physical media advocates call for PlayStation boycott over Sony's disc-free 2028 plan
Supporters of physical media are organizing a one-week PlayStation boycott in August to protest Sony's announced plan to phase out disc-based games by 2028. Backers of the campaign argue the move sends a clear signal that Sony's decision is unacceptable to a significant segment of its player base.
Pokémon card scalping prompts facial recognition checks at Japanese retailers
Some stores in Japan have introduced mandatory facial recognition systems to combat rampant Pokémon card scalping, marking an escalation in retailers' attempts to ensure cards reach genuine fans rather than resellers who have caused widespread stock shortages.
Security
Ernst & Young and Coca-Cola Both Confirm Data Breaches
Two major corporate data incidents surfaced on the same day. ShinyHunters, the extortion gang behind several high-profile breaches, claimed responsibility for a data breach at Ernst & Young, while Coca-Cola confirmed that data was stolen in a ransomware attack targeting its Fairlife brand. The back-to-back disclosures underscore the continued pressure on large enterprises from financially motivated threat actors.
Coca-Cola's confirmation of the Fairlife ransomware data theft adds a second major consumer-facing brand to the day's incident list, signaling that ransomware operators are actively pursuing household-name targets for maximum leverage.
CISA Adds Fortinet FortiOS and Arista VeloCloud Vulnerabilities to Known Exploited Catalog
CISA added two new entries to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 affecting Fortinet FortiOS and CVE-2026-16812 affecting Arista Networks VeloCloud Orchestrator On-Prem. Organizations running either product are directed to apply mitigations immediately, as inclusion in the KEV catalog indicates active exploitation in the wild.
Public PoC Released for Critical vBulletin Unauthenticated Remote Code Execution Flaw
A proof-of-concept exploit is now publicly available for a critical vBulletin vulnerability that allows unauthenticated remote code execution with a single HTTP request. The flaw routes attacker-controlled input directly into PHP's eval() function, meaning no login or user interaction is required. Administrators of self-hosted vBulletin installations are urged to patch immediately, as a working PoC in the wild dramatically shortens the window before mass exploitation.
Startups & Funding
Claude Code creator Boris Cherny speaks at YC Startup School 2026 following Opus 5 launch
Fresh off Anthropic's launch of Claude Opus 5, Boris Cherny, the creator of Claude Code, appeared at Y Combinator's Startup School 2026 to discuss what the newest models are capable of, how Claude Code was built, and what it means to develop products when the underlying AI capabilities keep accelerating. The session, hosted by YC's Diana Hu, offers a rare inside look at how Anthropic's flagship coding tool came to be and how its team thinks about building on rapidly shifting model foundations.
Travis Kalanick warns regulators will dominate as software starts controlling physical world
In a new a16z interview, Travis Kalanick drew a historical parallel for the regulatory battles facing today's founders, arguing that once software begins controlling atoms in the physical world, regulators become deeply involved — a dynamic he compared to disruptions seen 150 years ago. Kalanick also reflected on how CloudKitchens maintained years of stealth by exploiting media blind spots: even when someone tried to leak, he said, no one understood the story well enough to cover it.