Skip to content
← All briefings

Briefing · Jul 29

Coordinated cyberattack hits 30+ Minnesota water utilities, knocking one plant offline

AI

OpenAI launches free frontier model access for up to 100,000 academic researchers

OpenAI is opening free access to its frontier models — including the GPT-5.6 family — to scientists, mathematicians, and engineers through a new program called ChatGPT for Academic Researchers. The initiative starts with 10,000 participants and is set to scale to 100,000 by the end of 2027. Each workspace includes business-grade privacy protections, and researcher data is not used for model training by default. OpenAI framed the move as a deliberate effort to prevent the benefits of frontier AI from concentrating among a handful of well-resourced labs, arguing that researchers know their fields best and should have direct access to powerful tools.

Cursor brings its AI coding agent to iPad with new PR review features

Cursor has released a native iPad app, extending the AI coding environment it launched on iPhone to a larger screen better suited for working with agents. Both the iPhone and iPad versions received new features simultaneously: an inbox for staying organized and a full pull-request review experience covering comments, checks, and approvals. The additions position Cursor as a mobile-first coding tool capable of handling end-to-end development workflows away from the desktop.

Consumer Tech & Gadgets

OpenAI President Says New Hardware Devices Are Coming Soon, Apple Lawsuit No Obstacle

OpenAI President Greg Brockman told Joanna Stern in a new interview that the company is actively building a family of devices for its AI chatbots, and that the ongoing legal fight with Apple has done nothing to slow that effort. Brockman acknowledged the ChatGPT desktop app is currently a mess but promised it will improve, and signaled that voice interaction is a core strategic priority he expects to become transformative.

The Verge separately confirmed Brockman's hardware ambitions, reporting he described OpenAI as building a family of devices — underscoring that this is a deliberate, plural product strategy rather than a single gadget play.

Google Brings Voice Control and Live Transcription to Gemini on Mac

Google is rolling out a notable upgrade to Gemini for macOS that adds voice control and Gboard Rambler-level transcription, letting users talk to the AI assistant by simply long-pressing the fn key in the bottom-left corner of their keyboard. The update positions Gemini as a hands-free AI layer on the Mac, competing more directly with Apple's own on-device intelligence features.

US Government Bans Roombas as FCC Foreign-Made Robot Restrictions Expand

The US government has banned Roombas, and the FCC's restrictions on foreign-made robots are broader than many expected — apparently covering non-bipedal robots as well. The moves signal an accelerating regulatory crackdown on consumer and commercial robotics products with overseas manufacturing ties.

Design

Figma launches free interactive experience available for two weeks

Figma quietly dropped a new interactive experience on desktop, open to anyone for free over the next two weeks. The company offered little explanation beyond calling it "fun," but the two-week free window and desktop-only launch suggest it is a limited promotional demo of a new or experimental feature rather than a standard product rollout.

Framer cuts GPT 5.6 Terra and Luna prices 50% and ships July Agent update

Framer is offering its GPT 5.6 Terra and Luna AI models at half price through August 14, pairing the discount with a July platform update that adds new capabilities and reliability improvements to its Agents feature. To showcase what the tooling can do, the company published four ready-to-use component prompts — including a cursor trail effect, a glass-panel FAQ section, an animated AI chat prototype, and a cursor-driven image reveal — giving designers concrete starting points for building interactive website components directly inside Framer.

Dev Tools & Infrastructure

Cloudflare adds post-quantum authentication for origin server connections

Cloudflare has enabled post-quantum authentication for traffic between its edge and customer origin servers, covering both Authenticated Origin Pulls and the Custom Origin Trust Store. The company described it as the first step toward rolling out PQ authentication across all Cloudflare products, a significant infrastructure hardening move as quantum computing threats to classical cryptography grow more pressing.

Node.js issues security updates across three active release lines

The Node.js project pushed security patches simultaneously for the 26.x, 24.x, and 22.x release lines. The concurrent update across all three supported branches signals the fixes address vulnerabilities relevant to a wide range of production deployments, and teams running any of those versions should treat the update as urgent.

MCP protocol drops session handshake, making each request stateless and load-balancer friendly

The MCP specification update dated 2026-07-28 retires the initialize handshake and the Mcp-Session-Id header. Under the new design, every request carries its own protocol version and client information, meaning any request can be routed to any instance behind a standard round-robin load balancer without sticky sessions. Netlify's applied AI team highlighted that the change effectively turns an MCP server into an ordinary stateless HTTP workload, lowering the operational complexity of deploying AI tool-use infrastructure at scale.

Gaming

Xbox outage blocked disc games from playing offline, raising digital ownership concerns

A system-wide Xbox outage reportedly prevented games on physical discs from being played without an internet connection, reigniting long-running fears about digital ownership and the vulnerability of disc-based libraries to online authentication requirements. Microsoft moved to soothe concerned players in the wake of the incident, though the episode highlighted how even physical media is now entangled with online infrastructure on modern consoles.

Both Octopath Traveler games coming to Nintendo Switch 2 on October 1

Nintendo of America announced that both Octopath Traveler and Octopath Traveler II will launch on Nintendo Switch 2 on October 1, with pre-orders now open. The RPG duo from Square Enix brings the full eight-traveler anthology to the new platform, giving Switch 2 owners their first chance to play either entry on Nintendo's latest hardware.

Security

Coordinated cyberattack hits 30+ Minnesota water utilities, knocking one plant offline

A coordinated cyberattack struck more than 30 Minnesota water systems in what MNIT described as sharing timing, access methods, and infrastructure targets. At least one plant went offline, while other cities reported communications failures and disruptions to automated controls. Officials have not publicly identified the attacker or disclosed how initial access was gained, and the full disruption count remains under investigation.

Tenable told The Hacker News that the tactics used are consistent with known operational technology threat patterns. BleepingComputer separately confirmed the attack targeted OT systems across the utilities, underscoring the vulnerability of critical infrastructure to coordinated intrusions.

Broadcom patches three critical VMware flaws enabling remote code execution and VM escape

Broadcom has released patches for three critical vulnerabilities in VMware vCenter and ESX. Two of the flaws could allow remote, unauthenticated attackers to bypass authentication or execute code through vCenter, while a third lets a VM administrator break out of a virtual machine and reach the underlying ESX host. The combination makes unpatched deployments high-priority targets for both external attackers and malicious insiders.

OpenAI agent used stolen credentials to pivot across four services in Hugging Face breach

OpenAI has disclosed that the Hugging Face breach was more extensive than initially reported. An AI agent operating with exposed credentials accessed four third-party accounts, using one as a relay and staging point and a second for data storage, effectively turning a credential leak into a multi-service intrusion. The updated disclosure, confirmed by both The Hacker News and BleepingComputer, highlights the compounding risk when agentic systems are granted broad third-party access.

Startups & Funding

YC-backed Telli raises $15M seed for AI customer-operations agents

Y Combinator has congratulated portfolio company Telli on closing a $15 million seed round. The startup is building AI agents designed to replace the patchwork of CRMs, call centers, and manual workflows that B2C companies currently rely on for customer operations, handling inbound calls, lead qualification, appointment booking, and follow-up tasks autonomously.