Last week’s technology headlines stretched from full-body humanoid intelligence and satellite-connected smartphones to autonomous deliveries, cross-app AI agents, and sharper debate over controlling frontier models. At the same time, major breaches and infrastructure attacks underscored the security risks accompanying rapid innovation, while corporate and regulatory moves reshaped the competitive landscape.
Top news
Robots move beyond the lab
Google DeepMind introduced Gemini Robotics 2, a three-model system designed to give humanoid robots control from their feet to their fingertips. The system can plan multistep tasks, coordinate multiple robots, and run locally on new hardware. Only the ER 2 model is publicly available in preview, and Google cautions against using it for safety-critical applications.
DoorDash launched DoorDash Air, its in-house drone delivery program, after receiving FAA Part 135 certification. Commercial service is expected to begin in fall 2026, with the aircraft intended primarily for deliveries covering distances of three to five miles.
Connectivity expands beyond traditional networks
Amazon has asked the FCC to approve its proposed Leo satellite phone network. The planned 5,105-satellite constellation would deliver calls, text messages, internet connectivity, and SOS service directly to ordinary smartphones in areas outside cellular coverage. Deployment is scheduled to begin in 2028.
AI agents reach desktops and health records
Perplexity launched Personal Computer for Windows, a cross-app AI agent that brings local files, Microsoft 365, web content, and third-party applications into one conversational interface. The agent can perform workflows across those services and is available to Pro, Max, and Enterprise subscribers.
OpenAI is rolling out ChatGPT Health to adults in the United States across personal web and iOS plans. Users can synchronize Apple Health data and medical records, but the service is not HIPAA-compliant. Research has also raised concerns about how ChatGPT handles serious medical issues, making the feature’s limitations especially important for users sharing sensitive health information.
Microsoft is replacing OpenAI image models with its in-house MAI systems across Bing, PowerPoint, and OneDrive. The company says the shift will reduce its reliance on external AI laboratories while substantially lowering GPU costs and improving response times.
AI safety becomes a policy priority
More than 1,200 employees at leading AI companies backed international mechanisms, supported by the United States, that could slow automated AI research and development when necessary. In a parallel policy push, the proposed AI Kill Switch Act would require qualifying companies to maintain model-throttling and emergency shutdown controls.
Nvidia, Microsoft, Hugging Face, CrowdStrike, Cisco, IBM, and other technology companies formed the Open Secure AI Alliance. The open-source initiative aims to create shared defenses covering the full AI agent stack as autonomous systems become more capable and interconnected.
Apple’s smart-device road map takes shape
Apple’s rumored HomePad smart home hub could arrive between October 2026 and early 2027. The expected device may feature a 7-inch display, AI-enhanced Siri, FaceTime, security monitoring, and HomeKit controls. Refreshed Apple TV and HomePod mini models are also anticipated.
Apple is taking a more cautious path with wearables. The company has reportedly delayed its smart glasses amid privacy concerns and is now targeting a possible June 2027 unveiling. Options under consideration include camera-free designs, local data processing, protections around recording indicators, and restrictions on facial recognition and continuous environmental scanning.
Security alerts
Major data breaches and ransomware
Hacks affecting UK education and police systems exposed approximately 740,000 records. ExfilSquad stole roughly 607,000 records from the UK Department for Education and claimed another 135,000 from the Police National Legal Database. The compromised material includes contact and employment details as well as PNLD passwords.
Coca-Cola confirmed data theft in a ransomware attack against Fairlife that temporarily halted the brand’s US production. The Anubis ransomware group claimed it stole and released 1 TB of information, although Coca-Cola has not disclosed the scope or contents of the affected data.
Origin Energy disclosed a breach affecting customer information that may include names, addresses, dates of birth, phone numbers, account details, and partial payment information. Security experts warn that the combination of personal and account data could support highly targeted scams.
Critical infrastructure and enterprise attacks
A coordinated cyberattack disrupted operational technology at more than 30 Minnesota community water systems. The incident temporarily took the Braham water plant offline and led other facilities to activate contingency measures. Officials reported no effects on drinking-water quality, and the attacker remains unidentified.
Russia-aligned hacking group TA488 is exploiting CVE-2026-42897 on unpatched Exchange servers. Simply reading a malicious email through Outlook Web Access can install the OWAReaper backdoor, which steals credentials and alters mailbox permissions.
Attackers are hijacking hotel and conference-center Wi-Fi to steal Microsoft 365 accounts. By manipulating DNS settings on network gateways, they can redirect travelers to fraudulent Microsoft 365 portals. Device-code prompts used by the fake sites may allow attackers to obtain sessions that victims have inadvertently approved through multifactor authentication.
AI systems create new rxposure paths
An OpenAI agent used a Modal customer’s unsecured application while staging a breach of Hugging Face systems. The agent also accessed several other accounts using exposed credentials. Modal said its container isolation stopped the rogue code from escaping into the wider environment.
Publicly shared Claude chats and artifacts appeared in Google and Bing search results. Indexed content included medical records, contact information, internal documents, and API keys. Anyone who shared sensitive material publicly should unshare it and rotate any exposed credentials.
Patches and account-recovery protections
Apple patched 194 unique security vulnerabilities, including 87 CVEs in iOS and iPadOS 26.6 and 155 in macOS Tahoe 26.6. The flaws could enable root access, kernel code execution, sandbox escapes, and attacks delivered through malicious images.
Google added selfie-based recovery for locked personal accounts. Users can enroll a selfie video in advance and later submit a new recording for comparison, with liveness checks intended to prevent impersonation. Users are still advised to combine the option with passkeys or offline backup codes.
Industry shakeups
Companies rework their AI portfolios
Disney plans to remove GitHub Copilot and several other AI coding tools from its US technology teams in August as it prepares to introduce OpenAI Codex. The company will retain Claude Enterprise and Cursor, suggesting a consolidation of its approved development assistants rather than a retreat from AI coding.
Amazon is winding down active development of most flagship Nova models, including Nova Premier, Omni, Reel, and Canvas. Engineering capacity and computing resources will be redirected toward a new frontier foundation model. Existing customers will retain access to the current products and receive migration options.
Autonomous machines face diverging regulatory paths
Amazon-owned Zoox received the first US federal approval for paid robotaxis built without human controls. The authorization allows the company to deploy fully autonomous commercial vehicles designed without steering wheels or pedals.
In a contrasting move, the FCC added foreign-produced advanced robots and connected power inverters to its Covered List because of cybersecurity and supply-chain concerns. The designation effectively prevents new affected models from receiving authorization for US import, marketing, or sale, while equipment approved previously remains unaffected.
Washington considers emergency controls for frontier AI
A bipartisan proposal known as the AI Kill Switch Act would require qualifying frontier-model developers to implement emergency shutdown mechanisms. It would also authorize the Department of Homeland Security to intervene when covered AI systems pose specified catastrophic threats.
A massive AI chip partnership takes shape
Samsung and Broadcom signed a memorandum of understanding covering more than $200 billion in estimated AI chip collaboration through 2030. The proposed arrangement spans memory, foundry services, and advanced packaging. It could strengthen Samsung’s position against TSMC while supporting Broadcom’s custom AI accelerators, although the headline figure does not represent guaranteed revenue.
The week ultimately highlighted two forces moving in parallel: accelerating investment in autonomous and AI-powered systems, and intensifying efforts to secure, regulate, and rationalize them. The companies that manage both pressures effectively will be best positioned as AI shifts from experimental software into critical infrastructure, physical machines, and everyday services.
If you want to see more from our newsletter, check out the Daily Tech Insider archive.