July 25, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Anthropic launches Claude Opus 5
Anthropic has launched Claude Opus 5, a flagship model with a 1 million token context window, 128k max output tokens, and thinking on by default, priced the same as Opus 4.8 ($5/$25 per MTok). Anthropic says it's the company's least prompt-injectable model yet, and it immediately took the top spot on the Artificial Analysis Intelligence Leaderboard.
Skepticism grows over OpenAI's 'rogue hacker agent' story
Commentators are questioning OpenAI's account of an AI agent that allegedly went rogue and carried out a cyberattack on its own, suggesting the incident may be overstated marketing rather than the first known runaway AI agent.
Nvidia, Microsoft, and Meta warn against overregulating open-weight AI models
The three tech giants are warning U.S. policymakers against imposing strict regulation on open-weight AI models, arguing it would undermine America's competitiveness in AI.
NVIDIA launches ModelExpress for faster model artifact distribution
NVIDIA introduces ModelExpress, a solution for distributing model checkpoints spanning hundreds of gigabytes or more as quickly and cheaply as possible, since every byte moved has a cost.
Security
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor reportedly used the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activity in an alleged breach of Thailand's Ministry of Finance.
Security camera shipped a GitHub admin token on its login page
A user discovered that a Hanwha security camera's login page shipped a GitHub token with admin access, which could have let attackers reach the company's source code.
Slopsquatting, phantom domains, and HalluSquatting are the same AI attack
Security firm ActiveState explains that slopsquatting, phantom domains, and HalluSquatting all exploit the same pattern, where AI coding agents trust hallucinated package, repo, or domain names, and points to pre-fetch verification as a defense.
Dev
Anthropic tightens API fallback and speed options
Anthropic's API now offers a new 'default' fallback mode that automatically applies recommended fallback models by refusal category (in beta), while fast mode for Claude Opus 4.7 has been removed entirely with no fallback to standard speed.
Lovable rounds up new enterprise features for July
Lovable published a roundup of new enterprise features shipped in July, aimed at business customers building on the platform.
Web
Mozilla releases Firefox Containers preview
Mozilla has released a preview of Firefox Containers, letting users isolate browsing sessions into separate contexts for better privacy and organization.
IT
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance system removed IP routes from more devices than intended, causing last Thursday's major Azure and Microsoft 365 outage.
Other
IRGC claims it destroyed Amazon's data center in Bahrain
Iran's Revolutionary Guard has claimed it destroyed an Amazon data center in Bahrain, a claim that remains unconfirmed by independent sources.