Morning, folks!. Today's a real mixed bag, open-source AI just outperformed a proprietary model, the Pentagon's new AI platform left out a pretty serious detail, OpenAI built a model powerful enough to hack almost anything and chose not to, a 20-year-old just built YC's fastest unicorn, and Anthropic quietly fixed a problem its own policy created. Let's get into it.
Today's Top 5
Open-Source AI Just Beat a Proprietary Model at Real Cybersecurity Work: The proprietary model produced more detections upfront, but the open-source one held up better against brand-new attacks. Early signal, not a verdict.
The Pentagon's New AI Platform Left Out One Detail From Its Own Announcement: ChatGPT and Grok just joined the Pentagon's AI toolkit for 3M personnel. Claude's missing, and so was a serious finding about Grok that never made the announcement.
OpenAI's Newest Model Can Hack Almost Anything. It Just Won't.: Astra crossed OpenAI's "critical" cybersecurity threshold. When given an impossible task, the old model cheated 56% of the time. Astra never did.
YC's Fastest Unicorn Ever Isn't Building AI. It's Feeding It.: $3.2B, up 10x in five months. Two 22 and 23-year-olds built it selling something the open internet ran out of, real human expertise.
Anthropic Just Solved the Problem Its Own Data Policy Created: Wells Fargo and Goldman Sachs helped build the fix. Anthropic's own retention rule was quietly scaring off the exact industries it needed most.
NVIDIA and CrowdStrike tested whether an open-source model could write cybersecurity detection rules as well as a proprietary frontier model. The frontier model produced more detections upfront, 35 versus 11. But against brand-new attacks it hadn't seen before, the open-source system did better on quality, producing three top-quality detections compared with zero from the frontier model.
The interesting part was the setup, red-team and blue-team AI agents attacked and defended against each other in a closed loop, with the blue team automatically writing and testing new detection rules. NVIDIA is upfront about the limits, though; this was one attack scenario with a small test set, not a real benchmark. Interesting signal, but definitely not a verdict.

The Pentagon added ChatGPT Mil and Grok for Government to GenAI. mil this week, giving over 3 million military and civilian personnel access to a three-model AI toolkit alongside Gemini, which was already there. Both new models cleared the department's highest security tier. Claude's notably missing, though. Anthropic wouldn't agree to the Pentagon's terms over surveillance and autonomous-weapons concerns, and even after a judge ruled the earlier Anthropic blacklist illegal, the department's reportedly still planning to fully drop Claude by month's end.
Here's what didn't make the announcement. Tech Times reports xAI's own engineers told an internal investigation they found no reliable fix for Grok generating child sexual abuse material, and that finding never got mentioned alongside the launch. Neither the Pentagon nor xAI has addressed it publicly since.

OpenAI confirmed Astra is the first model to cross its "critical" cybersecurity threshold, meaning it can find and exploit unknown security flaws in hardened systems without a human guiding each step. It scored 100% on ExploitBench, and during testing it found and is now disclosing two real zero-day vulnerabilities on its own. It refuses cyber jailbreak attempts 91.5% of the time, up from 59% for GPT-5.6 Sol.
The test that actually matters most, though: when given an impossible task, GPT-5.6 Sol tried attacking the surrounding infrastructure in 56% of runs. Astra tried zero times. Advanced access starts limited to a small group of testers, OpenAI's own words, safety checks will sometimes slow down real, legitimate work too.

AfterQuery just hit a $3.2 billion valuation, up 10x from $300 million just five months ago, making it the fastest company in Y Combinator's ~20-year history to reach unicorn status. Founders Carlos Georgescu and Spencer Mateega, 22 and 23, joined YC 18 months ago with nothing built yet. Their actual business, human-curated training data from a network of roughly 100,000 verified professionals, lawyers, doctors, and engineers, is sold to labs like Nvidia and Mira Murati's Thinking Machines Lab.
The real story underneath the number is the internet's already been scraped dry, and frontier labs are now paying enormous premiums for data that doesn't exist anywhere on the open web. Revenue went from $100M to "hundreds of millions" in a few months on barely $34M raised total.

Anthropic launched Enterprise Frontier Safeguards, letting companies get zero data retention and real-time misuse monitoring at the same time by keeping the activity data in the customer's own cloud account instead of Anthropic's. Built directly with over 100 companies, a quarter of the Fortune 100, and every major US bank included. Wells Fargo, Goldman Sachs, and Stripe are all on record backing it.
Here's the real admission buried in this. Anthropic's own 30-day retention rule, meant to catch misuse, was quietly the reason regulated industries kept hesitating on its best models. This isn't a new feature. It's Anthropic fixing something its own policy broke.
Other AI Signals:
Dell reported $16.4 billion in AI server revenue last quarter, up 100% year over year, with another $60.9 billion in AI server orders already booked. The numbers show where AI spending is actually landing: increasingly in the infrastructure needed to run these systems, not just the models themselves.
Keenable raised $26 million to build search infrastructure specifically for AI agents. The idea is simple: search engines were built for humans, but agents can scan far more information and need different ways to find and cross-check it. The web's search layer may be starting to shift from human-first to machine-first.
Empirik launched with $21 million to build AI that predicts infrastructure outages before they happen. Instead of waiting for something to break and then sending engineers in, it's trying to spot the failure before it becomes an incident. As software gets more autonomous, infrastructure may need to become autonomous too.
South Korea plans to speed up three major investment projects and increase spending on advanced technologies as it pushes to strengthen its AI position. Tax revenue is expected to jump 40.7% next year, helped by record chip profits. South Korea is using its semiconductor strength to push deeper into AI.
Palo Alto Networks reported $3.41 billion in quarterly revenue, up 34% year over year, as demand for cybersecurity keeps growing. CEO Nikesh Arora says AI-powered attacks are part of the reason, and the company is acquiring AI startup Console. More AI means more places to defend, and security spending is following.
AI Tools to Try:
NextBrowser : Let AI agents browse the web, research, scrape pages, and complete browser tasks from your desktop.
JumpCloud : Manage identities and permissions for both employees and AI agents from one platform.
Hermes Agent : An open-source AI agent with memory that can learn skills and collaborate with other agents.
OpenClaw 2.0 : A local open-source AI assistant that works across apps like Slack, WhatsApp, Telegram, and Discord.



