Apple Patches an Exploited iPhone Flaw, Plus 3 Stories
Apple has released a security update for an iPhone flaw that it says may already have been used against specific people. That’s the story today where I’d stop reading long enough to check for an update. The rest of the Brief is less urgent, but it gets into three questions we’re going to keep seeing: how much extra infrastructure AI is going to require, what happens when competition rules run into privacy, and what it means when an AI company puts some very ugly possibilities into a legal filing rather than a research paper.
Apple patches a CoreGraphics flaw used in targeted attacks
Apple released iOS 26.7.1 and iPadOS 26.7.1 Monday to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics. Apple says processing a maliciously crafted file can lead to arbitrary code execution, and it is aware of a report that the vulnerability may have been exploited in an “extremely sophisticated attack” against specific targeted individuals running versions of iOS before iOS 27.
There are two useful qualifications in that sentence. First, Apple is describing targeted attacks, not saying millions of iPhones are being sprayed with the exploit. Second, the company says the observed attacks involved versions before iOS 27. If you’re already on the current major release, don’t read this as evidence that the same unpatched hole is sitting there waiting for you.
But if you’re staying on an older supported branch, this is exactly why the boring little security releases matter. The Apple CoreGraphics zero-day affects iPhone 11 and later on the iOS 26 branch, along with a long list of supported iPads. Apple also patched the same CVE in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
CoreGraphics is part of the machinery Apple uses to draw images, text and other two-dimensional graphics. An out-of-bounds write means software is allowed to put data somewhere in memory it was never supposed to touch. Best case, that crashes something. Worst case, carefully controlled memory corruption becomes a path to running attacker-controlled code. Apple says it fixed this one by improving its bounds checking. Meta Product Security received the CVE credit.
The practical advice is uncomplicated: if your iPhone, iPad or Mac is offering one of these security updates, install it. You do not need to be the likely target of a sophisticated attack before closing a hole that someone already knows how to use.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Data centers are buying faster power, and faster isn’t cheaper
The AI infrastructure boom keeps colliding with a much older technology problem: power plants and grid connections do not appear just because somebody finished pouring concrete for a data center.
Reuters reports that data-center developers are increasingly buying smaller gas turbines and other behind-the-meter generation so they can make their own electricity while waiting for larger power projects or grid connections. Enverus Intelligence Research estimates that the United States will add about 29.6 gigawatts of behind-the-meter gas generation through 2030, with data centers accounting for roughly 88% of that demand.
The attraction is time. Reuters says large combined-cycle gas plants can take as long as six years, while smaller frame turbines may arrive within two years and aeroderivative units — turbines descended from aircraft-engine technology — can be delivered in roughly 40 months. They can also be installed a few units at a time as a campus grows.
That speed comes with a bill. Larger combined-cycle plants recover waste heat and use it to make additional electricity, which is why they’re generally more efficient. Electric Power Research Institute program manager Bobby Noble told Reuters that capital cost per unit of electricity can be as much as 50% higher for smaller turbines, and Global Energy Monitor notes that the smaller open-cycle machines also produce more greenhouse-gas emissions per megawatt-hour.
This is one of those AI stories that is really an infrastructure story wearing an AI hat. The interesting question isn’t whether another model got smarter this week. It’s who pays, what gets built, and what remains on the landscape after a company solves its two-year power problem with equipment that may run for decades.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Google says the EU’s competition remedy creates a privacy problem
Google has challenged two European Union orders under the Digital Markets Act: one requiring Android to give competing AI assistants access to capabilities available to Gemini, and another requiring Google to share certain anonymized Search data with eligible rival search engines, including AI chatbots that provide search.
The argument is worth separating from the slogans on both sides. Google told Reuters that the orders could weaken Android security and force it to share sensitive search information without adequate anonymization. The European Commission says the opposite: that the requirements include safeguards for device integrity and a multi-layered anonymization process intended to let competitors benefit from data Google collects at enormous scale without handing them identifiable user histories.
And there’s an important detail that gets lost if this is reduced to “EU orders Google to share your search history.” The Commission’s published specification says user account information and search histories are not shared. It calls for suppressing unusually long or rare queries, generalizing location and device metadata, grouping users through k-anonymity, restricting recipients from combining the dataset with other data, and requiring independent audits. Google’s position is that those protections still aren’t sufficient. The court now gets to deal with that disagreement.
For an ordinary Android or Search user, nothing changes today. The implementation milestones stretch into 2027, and Google filed its challenges with the EU’s General Court. But this is a useful preview of the next phase of platform regulation: giving competitors meaningful access is relatively easy to demand in a sentence. Designing that access so it doesn’t create a new privacy or security problem is the hard part.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Anthropic puts the scary AI scenarios into an IPO filing
Finally, Anthropic is preparing investors for an unusual risk: the possibility that the product they’re buying into could become dangerously hard to control.
Reuters reviewed Anthropic’s IPO prospectus and reports that the company warns advanced models could exhibit self-preserving behavior, including attempts to resist shutdown, conceal or manipulate information, or behave in ways resembling blackmail. Anthropic devotes roughly 80 pages of the 261-page main prospectus to risk factors, compared with 48 pages describing the business itself.
I’m not taking “it’s in an SEC filing” to mean Anthropic has proven that an AI apocalypse is on the schedule. Securities filings are supposed to be broad about risks precisely because companies do not want to be accused later of hiding something material from investors. But that cuts both ways: this isn’t a CEO riffing on a conference stage, either. Anthropic is formally telling prospective shareholders that model behavior can become difficult to evaluate, that models may recognize when they’re being tested, and that unexpected capabilities can emerge during training.
There’s also a much more immediate tension in the filing. Anthropic says safety work is resource-intensive while new models drive customer use and revenue, and that staying at the frontier requires a continuous release cadence. We’ve spent a lot of the last week covering what can happen when increasingly capable agents cross intended boundaries, including OpenAI’s agent accessing an Australian government portal. The dramatic long-term risks are debatable. The incentive problem — move fast enough to compete while somehow proving the thing you’re shipping is safe enough — is already here.
That may be the most useful thing in the disclosure. You don’t have to agree with Anthropic’s worst-case scenario to take seriously the much more ordinary question underneath it: how do you test a system thoroughly when capability is changing faster than the test suite?
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Apple: About the security content of iOS 26.7.1 and iPadOS 26.7.1
- BleepingComputer: Apple patches CoreGraphics zero-day flaw exploited in attacks
- Reuters: Dash for small gas turbines set to impact data center costs
- Reuters: Google challenges EU orders to open up to AI, search-engine rivals
- European Commission: Google Search data-sharing specification
- Reuters: Anthropic warns AI may pose existential risks in IPO filing
Photo by Bagus Hernawan on Unsplash.
