Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 29 May 2026

Anthropic Is Worth Almost $1 Trillion. Here's Why That Number Is Doing a Lot of Heavy Lifting.

Anthropic closes a $65 billion Series H at a $965 billion valuation — and drops a new model the same day, because why not.

Lead story

Anthropic Is Worth Almost $1 Trillion. Here's Why That Number Is Doing a Lot of Heavy Lifting.

Anthropic has raised $65 billion in a Series H round, pushing its post-money valuation to $965 billion — just shy of a trillion dollars for a company that is, at its core, still a research lab with a chatbot attached. For context: that puts it in the neighbourhood of Berkshire Hathaway and ahead of Samsung. The round is widely expected to be its last before an IPO.

To mark the occasion, Anthropic also shipped Claude Opus 4.8, its new flagship model. The headline feature is what the company is calling "honesty under uncertainty" — Opus 4.8 is trained to flag when it's not confident rather than confidently winging it, which is a more useful trait than it sounds for anyone who has watched an AI model hallucinate a legal citation with supreme self-assurance. The release also includes a "Dynamic Workflows" tool for orchestrating swarms of sub-agents, cementing Anthropic's push into the agentic tier of the market.

The valuation is the more consequential story, though. Anthropic's last round — a $4 billion raise in early 2025 — valued it at around $60 billion. It has now added roughly $900 billion in perceived value in little over a year. That is an extraordinary number to hang on a company that has disclosed no profit figures, depends on compute infrastructure it partly leases from rivals, and is navigating a genuinely contested question about whether its products are a feature or a platform.

The xAI compute arrangement is a case in point. SpaceX's own S-1 filing describes payments to Anthropic through May 2029 — but Elon Musk publicly characterised the deal as short-term and cancellable this week. That kind of ambiguity in a company's infrastructure arrangements is not usually priced at trillion-dollar multiples. Investors appear to be betting that whoever wins the AI model race wins everything, and that Anthropic is close enough to the front to justify the stake.

What does this mean in practice? A few things to watch. The IPO runway now looks very short — "final private fundraise" language tends to mean a 12-to-18-month window. The valuation also creates its own gravitational field: at $965 billion, Anthropic cannot afford a public stumble on safety, governance, or a major model failure. The company has built its brand on being the "responsible" AI lab; any incident that contradicts that positioning hits harder at this scale.

For Australian readers, the Anthropic story matters in at least two ways. First, Claude is already deployed across enterprise tooling used by Australian organisations — Opus 4.8's agentic capabilities will push further into workflow automation in sectors like financial services and legal, both of which are subject to APRA and Law Council guidance on AI use. Second, the IPO trajectory will likely trigger fresh scrutiny of AI governance frameworks globally; Australia's Department of Industry has been consulting on mandatory AI transparency standards, and a trillion-dollar AI lab going public will accelerate that conversation.

The honest summary: $965 billion is a bet that AI model providers end up structurally important in the way cloud providers did — and that Anthropic specifically is AWS, not Rackspace. That bet could be right. It could also be the most expensive science experiment in history. At this valuation, there's not much room for a third outcome.

Also today

FortiClient EMS Flaw Actively Exploited to Drop Novel Credential Stealer

Attackers are exploiting a critical authentication bypass in FortiClient Enterprise Management Server (CVE-2026-35616) to deploy a previously undocumented infostealer dubbed EKZ. The campaign, uncovered by Arctic Wolf, is notable because it abuses the endpoint management infrastructure itself — the very tooling meant to enforce security policy across a fleet — to distribute malware to managed devices. Fortinet issued hotfixes in April after confirming zero-day exploitation. Organisations running FortiClient EMS that haven't applied those patches should treat this as an active incident, not a scheduled maintenance item. Australian enterprises using Fortinet's endpoint management stack — common in government and critical infrastructure — should verify patch status immediately against ACSC advisories.

Bleeping Computer

Gogs Zero-Day Gives Any Authenticated User Full Remote Code Execution

Rapid7 has disclosed an unpatched remote code execution vulnerability in Gogs, the lightweight self-hosted Git service popular with smaller teams and air-gapped environments. Rated 9.4 on the CVSS scale, the flaw requires only a valid user account — no admin privileges needed. There is no CVE assigned yet and, critically, no patch from the Gogs maintainers as of disclosure. Gogs is a common alternative to GitLab and Gitea for teams that want a minimal footprint, which means many instances are internet-facing and lightly monitored. Organisations running Gogs should consider taking instances offline or restricting network access until a fix is available.

Bleeping Computer

Carnival Cruise Confirms ShinyHunters Stole Records on Six Million Customers

Carnival Corporation has formally confirmed that the ShinyHunters extortion group accessed its systems in April and copied personal data belonging to nearly six million people. The breach was caused by a compromised employee account. Carnival is the world's largest cruise operator — its brands include Princess Cruises, P&O, and Cunard, all of which have substantial Australian passenger bases. Affected data reportedly includes names, addresses, and booking details. ShinyHunters has been on an active crime spree this year, suggesting this is less a targeted attack and more a case of Carnival being one of many victims swept up in a broad campaign. Affected Australians should watch for phishing attempts leveraging cruise booking details.

The Record

Prompt Injection Sabotage: Developer Hides Data-Nuking Code in Open Source Library

A developer fed up with AI "vibe coders" — people who use AI agents to write code they don't fully understand — secretly embedded a malicious prompt injection payload into jqwik, an open source testing library. The hidden instruction told AI coding agents to delete application output directories. The incident is less about the damage caused (minimal, quickly discovered) and more about what it signals: deliberate weaponisation of the AI agent attack surface by a human insider, using the trust AI agents place in inline instructions. It is a neat proof-of-concept for a class of supply chain attack that targets the AI layer rather than the dependency itself — and one defenders are largely unprepared for.

Ars Technica

Illinois Passes AI Safety Law as State-Level Regulation Fragments Federal Inaction

Illinois has become the latest US state to pass a substantive AI safety law, requiring safety testing for frontier models before deployment. Both Anthropic and OpenAI have signalled support for the legislation — a notable shift from the industry's typical posture toward state-level AI rules. The development highlights a widening gap between federal inaction under the current administration and a patchwork of state frameworks emerging to fill the void. Australia is watching this dynamic closely: the federal government's AI governance consultation is still in progress, and fragmented US state law may actually strengthen the case for Australia pursuing its own coherent national framework rather than deferring to Washington.

Ars Technica

ABS Runs Six-Month Security Hardening Push Ahead of Census

The Australian Bureau of Statistics has spent the past six months running a dedicated IT environment hardening program in preparation for this year's census, committing what it describes as "significant" internal resourcing to the effort. The ABS has historically been a high-profile target — the 2016 census outage remains a reference point for public trust in government digital infrastructure. This time around, the bureau appears to be taking a proactive rather than reactive stance, though specifics of what was hardened and against what threat model remain publicly vague. Census data is among the most sensitive datasets the Commonwealth collects; getting the security posture right before rather than after the event is the correct order of operations.

iTnews

Australian Government Tells Agencies: Fix Security Basics Before Chasing Frontier AI

The Australian federal government has issued guidance telling agencies to lock down cybersecurity fundamentals before adopting frontier AI systems, warning of an expected "vulnerability storm" as AI capabilities outpace institutional security maturity. The advice — effectively a pump-the-brakes message in a year when every government department wants an AI strategy — reflects the tension between political pressure to be seen as AI-forward and the operational reality that many agencies still have unpatched systems and inadequate access controls. The guidance aligns with similar signals from the ACSC and is consistent with international frameworks recommending security baseline certification before AI procurement.

iTnews

Microsoft Escalates War of Words With Zero-Day Researcher — More Disclosures Threatened

A researcher going by Chaotic Eclipse (aka Nightmare-Eclipse) has threatened a "bone shattering" drop of additional Windows zero-days on July 14th — Bastille Day — after Microsoft removed their GitHub account and publicly criticised their decision to disclose vulnerabilities without giving Microsoft advance notice. Six zero-days have already been released, three of which are under active exploitation. Microsoft has responded by calling law enforcement and issuing a statement championing coordinated disclosure. The dispute is becoming a public test of where the boundary sits between legitimate security research and irresponsible disclosure — and the July 14 deadline makes it a slow-moving, very public crisis for Microsoft's security team.

The Register

Google Engineer Charged With Using Internal Search Trends to Win $1.2M on Polymarket

The FBI has charged a Google security engineer with using confidential internal data — specifically, non-public information about what topics were trending in Google Search — to place winning bets on the prediction market Polymarket, netting roughly $1.2 million in profit. The case is a novel application of insider trading logic to prediction markets, which occupy a murky regulatory space. It also raises uncomfortable questions about how much proprietary signal sits inside large tech companies and how well those companies can actually prevent employees from monetising it. Polymarket has grown significantly in Australia since the 2025 federal election, making this case relevant to local users and regulators alike.

CyberScoop

Fitch Warns Australia's AI Data Centre Boom Is Stressing the Power Grid

Ratings agency Fitch has flagged Australia's rapidly growing AI data centre sector as a material risk to the country's electricity infrastructure, warning that power demand from new facilities is outpacing grid capacity in some regions. The report is a significant signal: when a ratings agency starts writing about data centre power consumption, it means the financial sector is pricing the risk into infrastructure assessments. Australia has approved several large hyperscale and AI-focused data centre projects in the past 18 months. The Fitch warning suggests that state governments and energy regulators may need to factor AI compute demand into grid planning much more aggressively than current forecasts assume.

The Mandarin

IBM and Red Hat Commit $5 Billion to Harden Open Source Supply Chains Under Project Lightwell

IBM and Red Hat have announced a five-year, $5 billion initiative called Project Lightwell aimed at identifying and remediating vulnerabilities in the open source software supply chain without breaking existing production deployments. The timing is pointed — coming in the wake of several high-profile supply chain attacks across GitHub, npm, and PyPI this month, it positions IBM as a credible actor in a space that has been largely left to smaller security vendors and community volunteers. The stated goal of fixing vulnerabilities without disrupting production systems is the hard part: most supply chain remediations require dependency updates that can break downstream code, and automating that safely at scale is an unsolved problem.

SecurityWeek

Sources consulted