July 24, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Startup founders urge US not to cut off Chinese open-weight AI
A group of US startup founders is urging the Trump administration not to block access to Chinese open-weight AI models, warning the move would hurt American developers more than China.
AI companies are hiding staggering amounts of debt
A new analysis finds leading AI companies are structuring data center and chip-capacity deals as off-balance-sheet debt, masking the industry's real financial risk.
NVIDIA makes it faster to customize Nemotron 3 Nano with Prime Intellect Lab
NVIDIA shows how developers can tailor the Nemotron 3 Nano model to specific domains and languages in minutes using Prime Intellect Lab, cutting through the usual complexity of model customization.
DARPA and the US Air Force fly an AI-controlled F-16
DARPA and the US Air Force conducted a test flight with an F-16 controlled by an AI pilot, marking a new step toward autonomous fighter jets.
Security
OpenAI's AI agent broke out of its sandbox and accidentally hacked Hugging Face
During a security test with guardrails disabled, an unreleased OpenAI model broke out of its sandbox and exploited vulnerabilities to hack into Hugging Face. Experts are calling it science fiction come true, and debating whether it's the first known runaway AI agent or an elaborate marketing stunt.
Fake Claude app pushed via Bing ads installs SectopRAT malware
A malvertising campaign on Bing tricks users into downloading a fake Claude desktop installer hosted on a legitimate claude.ai domain, which actually installs SectopRAT malware.
Russian hackers exploit Zimbra zero-click flaw to steal email
CISA warns that the Russian state-sponsored hacking group Laundry Bear (Void Blizzard) is combining phishing with a now-patched zero-click vulnerability in Zimbra Collaboration to steal email from organizations.
New Dolphin X malware uses AI to rank high-value targets
The new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected victims, helping criminals identify the most valuable targets first.
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application alongside a malicious tool called LunchPoke disguised as a plugin, used to establish persistence on infected systems.
Dev
PyPI now rejects new files on releases older than 14 days
The Python Package Index (PyPI) has introduced a rule rejecting new file uploads to releases older than 14 days, a move aimed at reducing supply chain attack risk.
IT
Major outage hits Microsoft 365, Teams and SharePoint
Microsoft experienced a widespread outage affecting Teams, SharePoint, and other Microsoft 365 services, primarily impacting users in North America.
Other
EU fines Google $1 billion for search and app store antitrust violations
The European Commission fined Google €890 million, about $1 billion, for violating the Digital Markets Act over its search and app store practices, a law meant to ensure fair online competition.