News Aug 18, 2026 👁 42

IT News Roundup: AI Infrastructure Deals, macOS Exploits, and Major Data Breaches - August 18, 2026

Stripe reportedly acquires AI gateway OpenRouter for more than $7 billion, a critical macOS Screen Sharing flaw is under active exploitation, and attackers claim large-scale data thefts from French tax systems and Fortune 500 Azure tenants.

The past day in IT has been dominated by the money and machinery behind AI, a fresh wave of actively exploited vulnerabilities, and some large-scale data theft claims. On the infrastructure side, Stripe reportedly agreed to buy AI model gateway OpenRouter for more than $7 billion while Nvidia disclosed a $21 billion stake in SpaceX - both signs of how capital is concentrating around the AI buildout. On the security front, a critical macOS Screen Sharing flaw is being exploited in the wild, GitLab shipped an out-of-cycle patch for a critical unauthenticated GraphQL bug, and attackers are claiming massive breaches at France's tax authority and among Fortune 500 Azure tenants. Meanwhile, OpenAI and Anthropic are cutting model prices as Chinese rivals close the gap, and a PBS station is fighting to recover seven decades of archives after its storage vendor disappeared.

Stripe Reportedly Acquires AI Gateway Startup OpenRouter for More Than $7 Billion

Stripe has reportedly finalized an agreement to acquire OpenRouter, the startup that gives developers a single gateway to hundreds of AI models, for more than $7 billion. The deal was first reported by Bloomberg and marks a dramatic valuation jump: OpenRouter was valued at roughly $1.3 billion when it announced its Series B in May. Its investors include Sequoia, Andreessen Horowitz, Menlo Ventures, and Alphabet's CapitalG.

The strategic logic is that AI applications increasingly need to move among multiple model providers rather than lock into a single vendor. That creates demand for a neutral orchestration layer handling model selection, routing by price or performance, billing, and reliability. OpenRouter has said it serves millions of users across hundreds of models, so the acquisition would position Stripe alongside its payments infrastructure as another piece of developer plumbing.

Stripe has not publicly confirmed the transaction and told TechCrunch that it does not comment on rumors or speculation, so the deal should still be treated as reported rather than formally announced. If it closes, the move validates AI model routing as a major infrastructure layer in its own right.

Source: TechCrunch

Nvidia Discloses $21 Billion Stake in SpaceX in SEC Filing

Nvidia disclosed in a Securities and Exchange Commission filing that it held roughly 122.8 million Class A shares of SpaceX worth about $21 billion at the end of the second quarter, as of June 30. The disclosure marks the first time the chipmaker has given the value of its position in Elon Musk's space company, which follows an announced exclusive arrangement to kit out SpaceX data centers.

The filing also revealed that Nvidia held about 214.8 million shares of Intel, valued at roughly $30 billion. Together the stakes underline how deeply Nvidia has moved beyond selling GPUs into financing and equity positions across the AI infrastructure ecosystem, from data center operators to energy developers to rival chipmakers.

Investors have been watching these circular relationships closely: Nvidia benefits when AI companies build more data centers because those facilities consume its processors and networking equipment. The disclosures give a rare public look at how much of the AI boom is being underwritten by the industry's own balance sheets.

Source: CNBC

macOS Screen Sharing Flaw Under Active Exploitation to Deploy Cryptominers

The Netherlands' National Cyber Security Centre (NCSC-NL) has warned that a critical authentication flaw in Apple's macOS Screen Sharing component is being actively exploited in the wild. The vulnerability, tracked as CVE-2026-65400, allows an attacker already on the network to authenticate to the built-in remote desktop service without valid credentials, effectively giving them full control of the machine.

Apple fixed the issue in emergency updates released earlier this month for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to NCSC-NL, threat actors have used the flaw to gain root access on internet-exposed Macs and deploy a Monero cryptocurrency miner.

The practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those with port 5900 reachable from outside the network - typically through router port forwarding. The warning is a reminder for anyone running Macs in a home or small office lab: patch promptly and keep remote desktop services off public interfaces.

Source: Ars Technica

GitLab Patches Critical Unauthenticated GraphQL Flaw (CVE-2026-19478)

GitLab has released security updates to address a critical vulnerability in its Community Edition and Enterprise Edition software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, is rated Critical with a CVSS score of 9.4.

The patch release arrived outside GitLab's usual twice-monthly schedule, five days after a routine update that carried no critical-rated issues. Fixes are available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11, and all self-managed installations from 18.2 onward should upgrade.

GitLab.com and GitLab Dedicated are already running the patched version, so hosted customers do not need to take action. For teams that self-host GitLab - a common choice in homelabs and small engineering organizations - this is one of those out-of-cycle critical releases worth acting on immediately.

Source: The Hacker News

French Tax Authority Breach Exposes Data of Around 678,000 People

France's Ministry of the Economy and Finance has disclosed a cybersecurity breach affecting approximately 678,000 individuals after an attacker gained unauthorized access to systems belonging to the General Directorate of Public Finances (DGFiP). The agency manages some of France's most sensitive tax and financial administration systems.

According to DGFiP, the threat actor accessed its systems in June and July using compromised credentials, with the unauthorized access suspended after detection. Stolen data reportedly includes both enterprise and personal tax-related information, though the exact scope remains under investigation alongside ANSSI, France's computer security agency.

The incident adds to a growing list of attacks targeting government agencies whose centralized databases contain information useful for identity theft, phishing, and financial fraud. Public-sector breaches carry unusually long consequences because citizens cannot simply change many of the underlying identifiers connected to government records.

Source: BleepingComputer

Hacker Claims 3.6 Million Azure Account Records Stolen From Fortune 500 Companies

A threat actor is claiming the exfiltration of millions of employee records from the Microsoft Azure infrastructure of multiple large organizations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. The actor says it gained access using compromised credentials starting July 31 and is now selling the allegedly stolen employee databases.

The claims have not been independently verified, but the pattern fits a well-documented trend: identity-based attacks against cloud tenants that bypass perimeter defenses entirely. When valid credentials are used, activity looks legitimate to most monitoring tools, which is why credential hygiene, MFA enforcement, and anomalous-sign-in detection remain the core controls for multi-tenant cloud environments.

For IT teams, the practical takeaways are to audit service accounts and long-lived tokens, enforce phishing-resistant MFA wherever possible, and review Azure sign-in logs for access from unusual geographies or new devices - especially for any organization named in the leak claims.

Source: BleepingComputer

OpenAI and Anthropic Cut Prices as Chinese AI Rivals Gain Ground

Leading US AI labs are releasing cheaper models in what is shaping up to be a full-blown price war, as cost-conscious customers increasingly switch to cut-price alternatives from Chinese rivals. OpenAI has reportedly cut the price of GPT-5.6 Luna by 80 percent - from $1 to $0.20 per million input tokens and from $6 to $1.20 per million output tokens - while Anthropic introduced Claude Opus 5 at $5 per million input tokens and $25 per million output tokens.

The pressure is coming from models such as DeepSeek's V4 Flash and Moonshot's Kimi K3, which benchmarking firm Artificial Analysis found deliver performance close to the US frontier models at a fraction of the cost. In one comparison, Anthropic's Opus 5 at medium effort delivered similar per-task performance and cost to Moonshot's Kimi K3 at maximum effort.

The shift marks a change in competitive dynamics for an industry that has largely been defined by a race for powerful, expensive systems. For developers and IT organizations running inference workloads, the price drops translate directly into lower operating costs - and more leverage when negotiating with model providers.

Source: Financial Times

PBS Station Fears Losing 50TB of Data After Cloud Storage Provider Vanishes

A PBS affiliate, Nine PBS, has lost access to more than 50TB of archival data - including 70 years of television history - after its contracted cloud storage vendor, Open Source Storage (OSS), went defunct. The station says it suddenly lost access earlier this year and is now suing Iron Mountain, the data center that hosts the physical servers holding the archive.

In a recent hearing, a judge ruled that Iron Mountain must hand over any physical devices holding the data and ordered Nine PBS to find a third party who can help retrieve the files. The case has drawn attention from archivists and sysadmins alike as a cautionary tale about vendor lock-in: the station's data was only as durable as its storage provider's solvency.

The story resonates well beyond broadcasting. For anyone running self-hosted infrastructure or relying on third-party storage, it reinforces the basics that homelabbers already practice - keep copies you control directly, verify backups are actually restorable, and avoid single points of failure in the supply chain between data and disk.

Source: Ars Technica


← Back to Blog