Sam's News — tech — 2026-08-18¶
Funding¶
8.5 Anthropic revenue run rate tops $65 billion as IPO looms¶
Anthropic's revenue run rate reached $65 billion as the company progresses toward an IPO and advances its Decart acquisition.
- Annualized revenue: $65 billion (July 2026), up from $9 billion (end 2025)
- $18 billion revenue increase in two months (May–July)
- Projected 2026 year-end: $100–120 billion
- Company last valued at $965 billion (May 2026)
- IPO expected fall 2026 at $2 trillion+ valuation
Sources: calcalistech.com RSS, Neowin RSS, The Tech Buzz RSS, CNBC RSS, TechCrunch AI Web Searched Update to: Anthropic Targets $200 Billion Revenue Goal Ahead of Planned IPO
AI¶
8 Etched's valuation doubles to $21 billion in one month¶
AI hardware startup Etched announced $700 million in funding led by Jane Street at a $21 billion valuation on August 18, 2026, more than doubling its July valuation of $10.3 billion. Jane Street deployed its first Etched cluster system and led the round after testing.
- Valuation raised to $21 billion (from $10.3 billion in July)
- $700 million funding round led by Jane Street
- Valuation increased ~$11 billion in one month
- Jane Street deployed first shipped AI cluster system
- Systems feature prefill chip and cluster-scale memory for any frontier model
Sources: TechCrunch AI Web Searched
AI Safety¶
8 OpenAI halts training runs after Astra model reaches critical cyber capabilities¶
OpenAI has paused significant training operations after determining that its upcoming Astra model may possess critical cybersecurity capabilities, prompting enhanced safety protocols.
Sources: Wired RSS
Security¶
7.5 CISA Flags Critical Ray Framework Flaw Exploited for Browser-Based RCE¶
CISA added CVE-2025-62593 (CVSS 9.4), a critical Ray distributed computing framework flaw, to its Known Exploited Vulnerabilities catalog on August 18, 2026. The vulnerability enables remote code execution via DNS rebinding attacks through web browsers by exploiting missing authentication on endpoints; Ray patched it in version 2.52.0, but unpatched instances face active exploitation by botnets and cryptocurrency mining campaigns.
- CVE-2025-62593 (CVSS 9.4) added to CISA KEV catalog August 18, 2026
- Affects Ray open-source framework with 43,500+ GitHub stars
- Remote code execution via DNS rebinding through Firefox, Safari browsers
- Ray patched in version 2.52.0
- RondoDox botnet and ShadowRay 2.0 actively exploiting unpatched instances
- CISA deadline: Federal agencies must patch by August 20, 2026
- CVE-2025-62593, CVSS 9.4 severity rating
- 3-day expedited patching deadline (vs. standard 14 days)
- Ray 2.52.0 fixes the vulnerability
- Exploited through phishing and malvertising; affects browser-based DNS rebinding attacks
- Ray: 237M total downloads, 7M downloads per week as of October 2025
Sources: The Hacker News AI Web Searched, The Register AI Web Searched
7.5 TWINLOOT malware leverages SharePoint and Teams for persistent credential theft¶
TWINLOOT is a modular Python implant discovered in July 2026 that operates entirely within Microsoft cloud services for command-and-control and credential theft. Initial access occurs via Teams social engineering; the malware uses SharePoint and Teams TURN servers to maintain persistence while harvesting credentials and enabling lateral movement.
- TWINLOOT discovered July 2026 by Ontinue's Cyber Defense Center
- 39 MB compiled payload (bootstrap-fat.pyc) containing Python runtime delivered via Teams social engineering
- SharePoint dead drop polls every 15 seconds; Teams TURN servers enable WebRTC relay-based interactive access
- Harvests credentials via bogus lock screens, establishes reverse SOCKS5 tunnels to internal targets on ports 445, 3389, 5985, 1433
Sources: The Hacker News AI Web Searched, The Register RSS
7 WebKit Vulnerabilities Patched in macOS and iOS Security Updates¶
Apple released security updates on August 18, 2026 addressing dozens of vulnerabilities across macOS and iOS. Updates patch 28+ WebKit flaws and over 120 additional bugs in kernel, audio, and other components that could enable crashes, memory corruption, data disclosure, sandbox escapes, and kernel memory attacks; no in-the-wild exploitation reported.
- macOS Tahoe 26.6.2 patches 28 security defects (21 WebKit-related)
- iOS/iPadOS 26.6.1 patches same 28 plus Telephony authentication bypass
- iOS/iPadOS 18.7.10 addresses 120+ bugs including 40+ WebKit vulnerabilities
- WebKit flaws could cause crashes, memory corruption, data disclosure, sandbox escape
- No evidence of in-the-wild exploitation; immediate patching recommended
Sources: SecurityWeek AI Web Searched, MacRumors Web Search
7 Apple patches image-processing vulnerability exploitable for spyware¶
Apple released security patches for a critical image-processing vulnerability (CVE-2026-65346) affecting iPhones, iPads, Macs, and Vision Pro that could enable zero-click spyware delivery. The integer-overflow flaw in the ImageIO framework resembles FORCEDENTRY, the exploit historically used to deliver NSO Group's Pegasus.
- CVE-2026-65346: integer-overflow in ImageIO framework
- Affects iPhone 11+, iPad Pro/Air/models, Mac, Vision Pro
- Patched in iOS 26.6.1 with improved input validation
- Zero-click delivery possible; similar to FORCEDENTRY/Pegasus exploit
- CVE-2026-65329: Telephony component flaw allowing network traffic interception (iPhone 11+)
Sources: The Register AI Web Searched
AI Policy¶
7.5 OpenAI discusses pacing model development amid cyber-critical capabilities¶
The provided page content discusses Meta's Muse Image AI tool launch on Instagram and WhatsApp, which is unrelated to the stated event about OpenAI discussing pacing model development amid cyber-critical capabilities. No substantive information about OpenAI's guidance on deliberate pacing of AI model development or cyber-critical capabilities was found in the supplied pages or search results.
Sources: Hacker News (front page) RSS
Technology¶
7 Google to relocate all Pixel smartphone production out of China¶
Google has instructed suppliers to cease all Pixel smartphone, smartwatch, and wireless earbud production in China beginning in 2027, shifting manufacturing to Vietnam and India. The move reflects U.S.-China tensions and supply-chain diversification; if completed, Google would join Samsung as the only major global smartphone brands without Chinese production.
- All Pixel production exits China beginning 2027
- Manufacturing shifts to Vietnam and India
- Google already produces high-end Pixel phones in Vietnam as of 2026
- Google would become second major brand (after Samsung) to fully exit China smartphone production
- Pixel shipments expected to rise 8–10% this year from ~12 million units
Sources: Nikkei Asia AI Web Searched, Business Standard AI Web Searched, Engadget RSS
7 Anthro Energy breaks ground on solid-state battery electrolyte factory¶
Anthro Energy broke ground on August 18, 2026, on a Louisville factory to manufacture battery electrolytes for solid-state and conventional batteries. The facility is designed to produce 25 gigawatt-hours annually—enough for 300,000+ electric vehicles—and will begin production in 2028.
- Factory groundbreaking: August 18, 2026 in Louisville, Kentucky
- Annual production capacity: 25 gigawatt-hours (supplies 300,000+ EVs)
- Production start: 2028
- Funding: $24.9M Department of Energy (Bipartisan Infrastructure Law), $18.4M ITC (Inflation Reduction Act), $2.3M Kentucky tax incentives
Sources: TechCrunch AI Web Searched