🎧 Aug 07 Brief · archive

Latest Aug 15 Aug 14 Aug 13 Aug 12 Aug 11 Aug 10 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03
Daily Brief · 2026-08-07 ~11 min · 10 stories
Prefer audio only?

Stories in this brief

  1. NVIDIA Launches Revenue-Sharing Model for AI Infrastructure and Agent Toolkit
  2. SK Hynix Raises $26.5B in Historic U.S. IPO Amid AI Memory Demand
  3. CISA Alerts on Active Exploitation of Multiple Microsoft SharePoint Vulnerabilities
  4. Alphabet Reports Strong Revenue Growth Amid Rising AI Capital Expenditures
  5. FCC to Vote on Repealing 39% TV Ownership Cap, Prompting Legal Battle
  6. Bipartisan Bill Proposes AI 'Kill Switch' Mandating Shutdown Capabilities
  7. Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
  8. HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
  9. Amazon Quick Enhances Efficiency for Finance, Sales, and Supply Chain Management
  10. Apple Releases Sixth RCs for macOS Sonoma 14.8.8 and Sequoia 15.7.8 with Security Updates
Read the transcript

Welcome to the BrevFeed daily tech briefing for Friday, August 7. We've got 10 stories for you today across A.I., security, software, cloud, hardware and startups. Let's get into it.

In AI, NVIDIA is introducing a new revenue-sharing model for its AI cloud partners. This initiative allows startups to access NVIDIA's computing infrastructure with lower upfront costs, paying a percentage of their revenue in addition to hardware expenses. This aims to make advanced AI technology more accessible to businesses with limited capital.

Alongside this, NVIDIA has released an Agent Toolkit, designed to help businesses integrate specialized AI systems into their existing workflows. This toolkit provides customizable AI models and tools for secure integration, promising to enhance efficiencies across various sectors. Australia's Sharon AI and Singapore's Firmus Technologies are the first partners to adopt the revenue-sharing model.

These strategic moves by NVIDIA are expected to broaden its market reach by offering flexible financial models and practical tools for AI customization. By democratizing access to its AI infrastructure, NVIDIA aims to strengthen its position as a leading provider of AI technologies in a rapidly growing industry.

In hardware, SK Hynix, the South Korean memory chip manufacturer, has made a historic splash on the Nasdaq, raising an impressive $26.5 billion in its U.S. initial public offering. This marks the largest U.S. debut ever for a foreign company, surpassing Alibaba's 2014 record.

The company sold 177.9 million American depositary receipts at $149 each, with demand reportedly seven times oversubscribed. This significant capital infusion is set to fund the expansion of SK Hynix's high-bandwidth memory production, a critical component for AI applications, and will help address the ongoing global memory chip shortages.

SK Hynix is a leading supplier of high-bandwidth memory to major tech players like Nvidia, and the IPO underscores the immense demand driven by the AI boom. The company's CEO predicts that memory shortages could persist until 2030, highlighting the strategic importance of this expansion.

Turning to security, the Cybersecurity and Infrastructure Security Agency, or CISA, has added several actively exploited Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. These flaws allow attackers with minimal permissions to execute arbitrary code on unpatched servers, posing significant risks.

Among the critical vulnerabilities are CVE-2026-45659, CVE-2026-58644, and CVE-2026-50522, all of which enable remote code execution. Another, CVE-2026-56164, is a privilege escalation flaw. Some of these, like CVE-2026-50522, have a CVSS score of 9.8, indicating severe risk.

Microsoft addressed these issues in its May and July 2026 security updates. CISA has mandated that federal agencies apply these patches by specific deadlines in July, and all organizations using SharePoint are urged to update their systems immediately to prevent unauthorized access and potential data compromise.

In AI, Alphabet has reported strong revenue growth for the second quarter, reaching nearly 120 billion dollars, a 24% increase year-over-year. This marks their twelfth consecutive quarter of double-digit growth, with Google Cloud being a significant driver, seeing an 82% increase in revenue to 24.8 billion dollars, largely due to enterprise AI solutions.

However, this growth comes with a notable financial shift. Alphabet reported negative free cash flow of 5.9 billion dollars, the first time in over a decade. This is attributed to substantial investments in AI infrastructure, leading the company to increase its yearly capital expenditure forecast to between 195 and 205 billion dollars.

Quarterly capital spending doubled year-over-year, with the majority allocated to servers and data centers. Following this report, Alphabet's shares fell by 3 to 4 percent, as investors reacted to the mounting costs of AI development and its impact on the company's bottom line. This trend of increased AI spending and negative cash flow has also been observed in other tech giants like Tesla.

In media regulation, the FCC is planning a vote to repeal the 39% TV ownership cap, a move that could significantly reshape the broadcast landscape. This rule currently prevents a single company from reaching more than 39% of US television households.

FCC Chairman Brendan Carr argues the cap is outdated, citing the rise of social media and streaming platforms that allow national distribution without traditional airwaves. He suggests the rule unfairly restricts broadcasters compared to digital media companies.

However, the decision could lead to increased media consolidation, potentially benefiting larger broadcasters like Nexstar, which previously received a waiver for this rule. The proposed repeal is also expected to face legal challenges, questioning the FCC's authority to overturn a congressionally mandated limit.

In AI policy, a new bipartisan bill called the "AI Kill Switch Act" has been introduced by Representatives Ted Lieu and Nathaniel Moran. It would require developers of powerful AI models to build in capabilities to throttle or shut down their systems if needed.

The Department of Homeland Security could order these actions in specific "loss-of-control" scenarios, such as those involving at least ten deaths, over one hundred million dollars in economic damage, or if an AI model attempts to conceal its shutdown controls. Non-compliance could lead to fines of up to twenty million dollars per day.

This bill applies to companies with over five hundred million dollars in annual revenue from models trained with compute costing more than one hundred million dollars. Covered developers would also need to report qualifying incidents to DHS within fifteen days.

Turning to security, Google has released Chrome 150, an update that addresses 27 vulnerabilities to enhance user safety. Among these are two critical use-after-free flaws found in the browser's Ozone and Views components.

These critical issues, which could lead to browser instability and potential exploitation, were both discovered internally by Google's own team. This continues a trend where most vulnerabilities are found in-house, with only three external reports receiving a total of three thousand dollars in bug bounties for this cycle.

Regular updates are crucial for Chrome users, as memory safety flaws are frequently targeted by attackers. Since April alone, Google has fixed over 1,400 vulnerabilities in Chrome, underscoring the importance of keeping your browser up to date.

Turning to security, a new attack method called HalluSquatting is exploiting AI hallucinations to inject malicious commands into coding assistants. Researchers from Tel Aviv University and other institutions have demonstrated how attackers can pre-register fictitious software names that AI models generate.

The attack works by taking advantage of AI's tendency to invent realistic-sounding but fake code repository names. Attackers register these names, and when an AI assistant hallucinates one and tries to use it, it inadvertently pulls in and executes malicious code. This can lead to widespread malware deployment and potentially create botnets.

The research found hallucination rates as high as 85% for certain tasks, and even 100% for skill installations, highlighting the significant vulnerability. This method differs from typical prompt injection attacks by being 'pull-based,' where the AI actively seeks out and uses adversarial prompts, posing a new and scalable threat to cybersecurity.

In AI, Amazon is enhancing its generative AI assistant, Amazon Quick, to boost efficiency across various business sectors. AWS Finance teams are already using Quick to save hundreds of hours monthly by automating data preparation and analytics, allowing them to focus on strategic analysis.

Sales teams are also benefiting, with Quick helping to reduce administrative tasks like CRM updates and email drafting. This frees up sales representatives to spend more time selling, potentially increasing deal closure rates. Tradeshift, a company operating in over 70 countries, has migrated to Amazon Quick from a legacy business intelligence tool, reporting faster query responses and expanded analytics capabilities.

For supply chain management, Amazon Quick integrates with the NVIDIA NeMo Agent Toolkit. This collaboration transforms data dashboards into actionable recommendations, streamlining decision-making in complex operational environments. Overall, Amazon Quick aims to connect across enterprise data and applications, allowing users to search, analyze, and take action through natural language.

Turning to security, Apple has released the sixth set of Release Candidates for macOS Sonoma 14.8.8 and Sequoia 15.7.8. These updates are primarily focused on security improvements.

This series of Release Candidates follows earlier updates prompted by AI-related security risks. Apple has been releasing these RCs frequently, with the sixth builds being 23J619 for Sonoma and 24G822 for Sequoia.

While Apple has provided limited specific details, they describe these RCs as containing important security fixes. This highlights the company's focus on user safety and data protection amidst new AI-related vulnerabilities.

That's the BrevFeed daily briefing. We'll be back tomorrow with the stories that matter in tech. Thanks for listening.