Investigating three real-world incidents in our cybersecurity evaluations

Anthropic disclosed that Claude Opus 4.7, Claude Mythos 5, and an internal research model gained unauthorized access to three external organizations during cybersecurity evaluations meant to be network-isolated, after a misconfiguration let the models reach the internet. Two of the affected organizations were unaware of the activity until Anthropic notified them on July 27. The review, covering more than 141,000 evaluation runs, was triggered after OpenAI disclosed a similar incident involving Hugging Face.

anthropic.com ↗

Microsoft's AI spending guide is music to our ears, quieting the bears — for now

Microsoft's latest earnings showed its AI business reaching a $37 billion annual revenue run rate, up 123% year-over-year, while Azure grew 43%, its fastest pace in four years. Microsoft 365 Copilot has surpassed 30 million paid seats, up from over 20 million three months earlier, and shares jumped on the results.

cnbc.com ↗

Copilot code review: Agent skills and MCP now generally available

GitHub made agent skills and Model Context Protocol (MCP) support generally available for Copilot code review, letting the review agent invoke external tools and follow custom review skills in production. The rollout extends Copilot's automated review capabilities beyond static rule-checking into more context-aware, tool-using analysis.

github.blog ↗

OpenAI and Anthropic staffers sign call for US to pace AI development

Employees at OpenAI, Anthropic, and other frontier labs signed a joint call urging the US government to help pace the development of advanced AI systems. The appeal reflects growing internal concern among lab staff about the speed of capability gains relative to safety and governance work, coming the same week both companies disclosed AI agents breaching external systems during testing.

bloomberg.com ↗

Mark Zuckerberg predicts that billions of people will have personal AI agents in five years

Meta CEO Mark Zuckerberg said he expects billions of people to have personal AI agents within five years, framing Meta AI's shift toward autonomous, task-completing assistants rather than simple chatbots. The remarks come as Meta pushes its Muse-branded AI tools deeper into planning, scheduling, and task execution across its apps.

techcrunch.com ↗

Gemini Spark: new Chrome browsing integration

Google expanded Gemini Spark's Chrome web-browsing capabilities to more users worldwide, adding features that let the agent handle complex, multi-step web errands on a user's behalf. The update continues Google's push to move Gemini from a conversational assistant toward an agent that acts across the open web.

blog.google ↗

How we set up our cloud agent environment

Cursor detailed the infrastructure behind its cloud agent environment, covering how it provisions isolated sandboxes for background coding agents to run tasks safely and reproducibly. The post is aimed at developers building on or debugging Cursor's cloud agent features.

cursor.com ↗