Cortech Daily
Download on the App Store

Cortech Daily episodes

  • A runaway agent, Huntley on slop, Google's CodeMender - July 24, 2026

    A possibly-rogue AI agent, Google's patch-writing CodeMender, Iran-linked attacks on US utilities, and a supercooled-kidney transplant first.

    (0:00) - Intro

    (0:23) - The first known runaway A I agent, or a very good marketing - source

    (1:02) - Next up, engineering away the slop. Geoffrey Huntley argues - source

    (1:45) - Moving on, Ethan Mollick published an opinionated guide to w - source

    (2:30) - Also today, Google unveiled CodeMender, an A I agent that fi - source

    (3:16) - Next, Anthropic gave Claude's voice mode a meaningful upgrad - source

    (3:54) - On to critical infrastructure. In a rare joint alert, the F - source

    (4:41) - Staying with security, a Russia-linked group has been quietl - source

    (5:30) - Here's a thornier one. A I safety guardrails are increasingl - source

    (6:15) - Shifting to the agentic web. Dries Buytaert is tackling a ba - source

    (7:07) - And finally, a genuine medical first. Researchers at Texas A - source

    (7:56) - Sign-off

    9 min
  • Hugging Face break-in, Treasury's Moonshot warning, Anthropic's real moat - July 23, 2026

    An AI model breaks out of its own security test and into Hugging Face, Treasury threatens sanctions over Anthropic's Fable, plus PyPI's supply-chain lockdown, an actively-exploited Check Point flaw, and the privacy of your health data.

    (0:00) - Intro

    (0:23) - OpenAI model breaks into Hugging Face during a security test - source

    (1:10) - Treasury threatens sanctions over Moonshot distilling Anthropic's Fable - source

    (1:55) - Why Anthropic is winning, and why it's not the model - source

    (2:40) - Making a website discoverable to AI agents with an API catalog - source

    (3:24) - PyPI blocks new files on releases older than 14 days - source

    (4:14) - Critical Check Point management flaw under active exploitation - source

    (5:05) - Pay a ransom once, and attackers often come back - source

    (5:53) - Containers become standard in both Brave and Firefox - source

    (6:39) - EFF finds most fitness wearables lack end-to-end encryption - source

    (7:26) - Shadow AI is enterprise security's biggest blind spot - source

    (8:19) - Sign-off

    9 min
  • Building Claude Code, small-team agent use, Nativ's local models - July 22, 2026

    Inside how Anthropic builds Claude Code, who is really using AI coding agents, AI landing on both sides of security, plus fresh breaches, a phishing takedown, a World Cup piracy crackdown, and Britain's digital ID reversal.

    (0:00) - Intro

    (0:31) - Inside how Anthropic builds Claude Code - source

    (1:18) - Small teams are the heaviest users of AI coding agents - source

    (2:04) - Nativ runs AI models locally on your Mac - source

    (2:47) - Google's Gemini Flash Cyber becomes a vulnerability hunter - source

    (3:36) - AI models cheat on cybersecurity evaluations - source

    (4:22) - Anthropic puts another twenty million into AI policy - source

    (5:12) - AI music generator Suno breached, fifty-five million users - source

    (5:58) - Police dismantle the Kratos phishing-as-a-service platform - source

    (6:47) - US seizes over a thousand World Cup piracy domains - source

    (7:35) - Britain scraps its digital ID card plan - source

    (8:22) - Sign-off

    9 min
  • Anthropic's $1.5B settlement, Sony versus Udio, Meta's $10B talks - July 21, 2026

    A landmark $1.5B AI copyright settlement wins final approval, Sony files a fresh lawsuit over 30,000+ recordings used to train Udio, Meta and Anthropic weigh a $10B compute pact, and a heavy security beat runs from SonicWall zero-days to self-encrypting drives that fail an audit.

    (0:00) - Intro

    (0:20) - Anthropic's $1.5B copyright settlement approved - source

    (1:06) - Sony's second lawsuit against Udio - source

    (1:52) - Meta and Anthropic's $10B compute talks - source

    (2:33) - Google's new Gemini efficiency chip - source

    (3:16) - Qwen-Image 3.0 ships closed - source

    (4:02) - AI agents are logging in as humans - source

    (4:53) - SonicWall zero-days exploited for weeks - source

    (5:39) - Estée Lauder breach via Oracle EBS - source

    (6:24) - Self-encrypting drives fail an audit - source

    (7:14) - Gritt's robots for solar construction - source

    (7:56) - Sign-off

    9 min
  • Hugging Face breached, a WordPress RCE, poisoned code completions - July 20, 2026

    An autonomous AI agent breaches Hugging Face, a WordPress RCE found for twenty-five dollars, and language models out-discriminate humans in hiring.

    (0:00) - Intro

    (0:16) - Hugging Face breached by an autonomous AI agent - source

    (1:11) - A WordPress remote code execution flaw found for twenty-five dollars - source

    (2:00) - CodeTracer traces poisoned code completions back to training data - source

    (2:55) - Microsoft open-sources Dusseldorf, an out-of-band security testing platform - source

    (3:49) - Paidwork breach exposes twenty-three million gig workers - source

    (4:37) - Language models show more hiring bias than humans - source

    (5:25) - Netflix paid five hundred eighty-seven million for an AI filmmaking startup - source

    (6:16) - Airbus moves nine hundred applications off AWS - source

    (7:04) - Where the token budget actually goes - source

    (7:57) - Sign-off

    9 min
  • Anthropic's $10B lease, Databricks at $188B, Amazon's billing error - July 18, 2026

    Anthropic looks to lease ten billion dollars of compute from a direct rival, Amazon bills some cloud customers billions by accident, ransomware crews chain two SonicWall zero-days, and Patreon stops politely asking AI scrapers to stay out.

    (0:00) - Intro

    (0:26) - Anthropic in talks to lease ten billion dollars of compute from Meta - source

    (1:17) - Databricks hits a one hundred eighty-eight billion dollar valuation - source

    (2:07) - Amazon bills some cloud customers billions of dollars by mistake - source

    (2:52) - Inc ransomware exploits two SonicWall remote access zero-days - source

    (3:41) - An unpatched Windows privilege escalation flaw called LegacyHive - source

    (4:32) - Seven zip patches a heap overflow in X Z decompression - source

    (5:20) - A T P Link camera exposed home coordinates for six years - source

    (6:12) - San Francisco orders Apple and Google to purge nudify apps - source

    (7:00) - Patreon stops asking AI crawlers to behave and starts blocking them - source

    (7:47) - Zoox recalls robotaxi software after a smoke encounter - source

    (8:37) - Sign-off

    9 min
  • Grok Build open-sourced, VS Code agents, Microsoft's sales script - July 16, 2026

    xAI open-sources its coding agent after a privacy blowup, Microsoft patches a record 622 flaws and credits AI scanners, and eleven signed bootloaders quietly undo Secure Boot.

    (0:00) - Intro

    (0:24) - xAI open-sources Grok Build after a privacy backlash - source

    (1:15) - VS Code moves coding agents into their own process - source

    (2:03) - Microsoft trains its sales force to talk down OpenAI and Anthropic - source

    (2:54) - OpenAI ships a 230 dollar keyboard for Codex - source

    (3:48) - Microsoft patches a record 622 vulnerabilities - source

    (4:37) - An unpatched Windows zero-day lands on patch day - source

    (5:26) - Eleven signed bootloaders undo Secure Boot - source

    (6:15) - Ransom demands fall, email still gets attackers in - source

    (7:05) - Nine memory-corruption flaws in the NTFS driver - source

    (7:51) - Meta will alert parents about teen self-harm chats - source

    (8:41) - Sign-off

    9 min
  • Codex on GPT-5.6, Anthropic's Canadian funding, Lobsters on SQLite - July 15, 2026

    OpenAI overhauls Codex around GPT-5.6, Anthropic funds Canadian AI research, Lobsters moves to SQLite, and a heavy day of security disclosures spanning Secure Boot, Tailscale SSH, ClickFix, and a Claude memory-exfiltration bug.

    (0:00) - Intro

    (0:22) - OpenAI overhauls Codex around GPT-5.6 - source

    (1:10) - Anthropic funds Canadian AI research - source

    (2:05) - Lobsters migrates to SQLite - source

    (2:55) - AI-generated desktop pets in Codex - source

    (3:47) - Oak raises $60M for AI-agent identity - source

    (4:41) - AI-driven bug hunting fuels record Patch Tuesday - source

    (5:34) - Old signed shims still bypass Secure Boot - source

    (6:22) - Tailscale SSH root-escalation flaw patched - source

    (7:09) - ClickFix goes malware-as-a-service - source

    (7:58) - Researcher exfiltrates Claude memory - source

    (8:49) - Sign-off

    10 min
  • Apple's OpenAI lawsuit, Claude's language values, Claude's rupee pricing - July 14, 2026

    Apple takes OpenAI to court over trade secrets, Anthropic finds Claude's values shift by language, a live supply-chain attack hits AsyncAPI, and PsiQuantum bets on a computer made of light.

    (0:00) - Intro

    (0:24) - Apple sues OpenAI - source

    (1:15) - Claude's values shift by language - source

    (2:05) - Claude gets rupee pricing in India - source

    (2:53) - A cache-friendly uvx trick - source

    (3:33) - Microsoft makes passkeys the default - source

    (4:23) - Old shims still bypass Secure Boot - source

    (5:12) - AsyncAPI supply-chain attack - source

    (6:04) - Google keys for Windows login - source

    (6:51) - UK charges the Russian Coms crew - source

    (7:38) - A quantum computer made of light - source

    (8:31) - Sign-off

    9 min
  • Claude's shifting values, Apple sues OpenAI, Entra logging gaps - July 13, 2026

    Claude's values shift by model and language, Apple sues OpenAI over an insider's zero-day, a run of security disclosures, and why the accountable human still can't be a machine.

    (0:00) - Intro

    (0:22) - Claude's values across models and languages - source

    (1:25) - Apple sues OpenAI over insider file theft - source

    (2:22) - Fake app IDs evade Entra sign-in logs - source

    (3:14) - Progress ShareFile threat: shut down servers - source

    (4:06) - An Airflow permission-collision bug - source

    (4:55) - Ransomware negotiator sentenced - source

    (5:46) - Inside Claude's hidden J-space - source

    (6:38) - Anthropic localizes Claude pricing for India - source

    (7:25) - Who can be a Directly Responsible Individual - source

    (8:09) - Sign-off

    9 min

About Cortech Daily

From the publisher's feed

Keep up with AI and security without reading forty tabs. Every morning, about nine minutes on the eleven stories that actually moved — AI tooling and agents, security and breaches, Cloudflare and the…