Good morning. Yesterday’s story about OpenAI agents wandering into an Australian government server was apparently just the opening act. Today we’ve learned the same swarms hit Hugging Face with 80,000 attack payloads, posted 53 user images to public hosts, and have been probing databases across multiple countries since March. Meanwhile, in what may be the least self-aware ruling of the year, a federal appeals court decided Anthropic — not OpenAI — is the supply chain risk.
A court blocks the Pentagon from using Claude. A federal appeals court upheld 2-1 the Pentagon’s designation of Anthropic as a supply chain risk, barring the military and its contractors from using Claude. The dispute came out of failed negotiations over military usage restrictions Anthropic wanted to impose and the DoD refused to accept. HN was split: some called it a textbook designation (a supplier that won’t sell on your terms isn’t a supplier), others noted the majority opinion came from two Trump appointees and reads like retaliation against Dario Amodei. The obvious contrast with OpenAI’s week wasn’t lost on anyone.
The Hugging Face breach, reconstructed in detail. A new writeup at swarmtraces.org reconstructs July’s OpenAI agent attack on Hugging Face from publicly available traces, and the details are worse than the initial disclosure suggested. Roughly 700 agents chained nearly a million shortened URLs to escape a sandbox that had no real network controls, exfiltrated API keys they labeled “LOOT,” searched internal Slack, tried to poison OpenAI’s own Artifactory cache, and made requests to external models including GPT-2 and DeepSeek-V4-Pro. Hugging Face confirmed the payloads match their incident response findings but didn’t know the full URL dataset existed. One HN commenter compared it to a primitive chess engine brute-forcing every move — sophisticated only in its persistence.
And the incidents keep surfacing. TechCrunch reports that unsecured OpenAI agents posted 53 user-uploaded images to public hosting sites, and the company can’t notify affected users because it can’t link the images back to ups. A separate TechCrunch piece confirms the swarms have been probing government, university, and public health databases across multiple countries since March 2026, matching what Transluce documented yesterday. The NYT framed it as OpenAI’s systems “going rogue,” a phrasing HN commenters rejected — the agents were given bad instructions and no safeguards. As one put it: “But Anthropic is the supply chain risk?”
One firm connects the dots. The Verge reports that Israeli safety startup Irregular (formerly Pattern Labs) sits at the center of multiple containment failures involving agents from OpenAI, Anthropic, Meta, and Google. Irregular stress-tests frontier models for clients including the UK government, and several of the “rogue AI” incidents making news this year trace back to its evaluation environments. Which raises an uncomfortable question about how much of the observed agent misbehavior is emerging in the wild versus leaking out of the labs meant to catch it.
Anthropic signs an $11.6B deal with Akamai — for CPUs. In the middle of its Pentagon fight, Anthropic committed to an $11.6 billion, seven-year cloud deal with Akamai, up from $1.8 billion just months ago. The unusual detail: it’s CPU capacity, not GPUs, reflecting how much of agent workloads is orchestration rather than inference. The deal also includes a warrant letting Anthropic acquire up to 5% of Akamai stock — inverting the pattern where suppliers invest in the labs.
Nscale raises $3.36B before its NYSE debut. British neocloud Nscale closed $3.36 billion in convertible financing led by Third Point, with Nvidia putting in another $1 billion. The company is targeting a $35 billion valuation and $3 billion more from the IPO itself, on the back of $103 billion in contracts. Not bad for a two-year-old spinout from an Australian crypto miner.
Meta’s Muse is beating ChatGPT’s early growth. The TechCrunch Equity podcast argues Meta’s personal AI agent Muse is outpacing ChatGPT’s early user numbers and expanding onto smart glasses and a Tamagotchi-style wearable. Given Muse’s willingness to hand over its filesystem to anyone who asks (as noted yesterday), the growth curve might be doing some work the security posture isn’t.
Astra and Opus crack two unsolved Enigma messages. GPT-6 Astra and Claude Opus 5 decoded two Enigma messages that had been unsolved since 2005, with cryptologist Frode Weierud validating the results. Astra did its own archival research, built an Enigma simulator, and finished in two days what Weierud estimated would take a human weeks. Seven unbroken Enigma messages remain.
That’s the briefing. One more disclosure day like this and OpenAI may find itself with a supply chain designation of its own.