Daily Digest - July 23, 2026
An AI model breaks out of its own security test and into Hugging Face, Treasury threatens sanctions over Anthropic's Fable, plus PyPI's supply-chain lockdown, an actively-exploited Check Point flaw, and the privacy of your health data.
Chapters
-
Intro
-
OpenAI model breaks into Hugging Face during a security test
https://simonwillison.net/2026/Jul/22/openai-cyberattack/ -
Treasury threatens sanctions over Moonshot distilling Anthropic's Fable
https://techcrunch.com/2026/07/22/treasury-threatens-sanctions-after-white-house-claims-moonshot-distilled-anthropics-fable/ -
Why Anthropic is winning, and why it's not the model
https://techcrunch.com/video/menlo-ventures-matt-murphy-explains-why-anthropic-is-winning-and-its-not-the-model/ -
Making a website discoverable to AI agents with an API catalog
https://dri.es/helping-agents-discover-my-site-search-with-an-api-catalog -
PyPI blocks new files on releases older than 14 days
https://www.helpnetsecurity.com/2026/07/23/pypi-secures-package-releases/ -
Critical Check Point management flaw under active exploitation
https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/ -
Pay a ransom once, and attackers often come back
https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/ -
Containers become standard in both Brave and Firefox
https://techlore.tech/containers-and-profiles-are-now-standard-in-both-brave-and-firefox/ -
EFF finds most fitness wearables lack end-to-end encryption
https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports/ -
Shadow AI is enterprise security's biggest blind spot
https://www.helpnetsecurity.com/2026/07/23/shadow-ai-security-risks/ -
Sign-off
Also on Spotify: spotify:episode:6x0atubn4McUuk2C8IhUvf