:

THE DAILY BRIEF

MONDAY, JULY 20, 2026

■ TOP STORY

HELION RAISES $465M TO POWER MICROSOFT DATA CENTERS

Fusion startup Helion has raised $465 million to accelerate construction of a power plant for Microsoft, targeting completion by 2028. The funding marks a significant milestone in bringing commercial fusion energy online to meet growing AI infrastructure demands.

► WHY IT MATTERS: This signals that tech giants view fusion as a critical near-term solution to the power crisis threatening AI scalability, not just a distant moonshot.

6 SOURCES
2.

ANTHROPIC OPEN-SOURCES AI SECURITY VULNERABILITY TOOL

Anthropic has released an open-source framework for using AI to discover code vulnerabilities, now generating significant developer interest with 178 points and 61 comments on Hacker News. The tool targets automated vulnerability detection in applications.

Open-sourcing security tools democratizes vulnerability discovery, but may also lower barriers for attackers using the same methods.

3 SOURCES
3.

APPLE APP STORE HITS $1.4T IN SALES, 90% COMMISSION-FREE

Apple reported $1.4 trillion in cumulative App Store billings and sales, up from $1.3 trillion previously, with $149 billion in digital goods sales and 90% of transactions occurring without Apple taking a commission. The numbers highlight Apple's ecosystem scale while responding to regulatory scrutiny.

Apple's disclosure of commission-free transactions is a defensive play against regulators and competitors challenging its 30% cut on paid apps.

7 SOURCES
4.

OPENAI UPGRADES GPT-5.5, RETIRES LEGACY MODELS INCLUDING O3

OpenAI is rolling out improvements to GPT-5.5 Instant while announcing the retirement of multiple legacy models, including o3, as part of a model consolidation strategy. The move forces developers to migrate to current versions.

OpenAI's aggressive model retirement schedule shortens the lifespan of stable API versions, increasing maintenance burden on production applications.

3 SOURCES
5.

IRONWORM MALWARE INFECTS 36 NPM PACKAGES IN SUPPLY CHAIN

A new supply-chain attack has compromised 36 packages on npm with infostealer malware called IronWorm, targeting Node.js developers and their downstream users. The attack demonstrates continued vulnerability in open-source package registries.

Every npm install remains a potential attack vector; this is the third major supply-chain incident in months, suggesting no real progress on registry security.

1 SOURCE

■ COMPILED BY THE NEWSROOM ■ SOURCES: 15 RSS FEEDS

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.