Tonight’s urgent technology story is an actively exploited flaw in JetBrains TeamCity—a reminder that the server building your software can be just as sensitive as the production server running it. Apple’s iCloud Private Relay faces a separately reported WebKit privacy weakness, prominent Google AI researchers are starting a scientific-discovery company, Anthropic is assembling a chip-design team, AMD posted a record quarter, Shopify says AI referrals are adding commerce traffic, and Cloudflare is adding identity and tool controls for workplace agents. Here is The IT Guys’ source-backed 5 PM recap for Wednesday, August 5, 2026.
🎧 Listen to the recap
Locally synthesized narration by Jennifer Hudsen for The IT Guys.

Tonight in 60 seconds
CISA put CVE-2026-63077 in its Known Exploited Vulnerabilities catalog; TeamCity build servers need immediate attention.
Researchers found WebKit paths that can reveal a real IP address; TechCrunch says it reproduced the proof of concept.
Jeff Dean and other senior researchers are forming Discovery Loop to automate scientific and engineering experiments.
The company confirmed a custom-chip team—but this is an engineering effort, not a product launch.
Revenue reached $11.536 billion; Data Center revenue rose 107% year over year to $6.7 billion.
Shopify says AI referrals tripled while traditional search still supplied roughly one-third of storefront sessions.
1. CISA says the TeamCity flaw is being actively exploited
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on August 5. CISA’s entry describes an unauthenticated deserialization flaw in JetBrains TeamCity On-Premises that can produce remote code execution through the agent polling protocol.
That placement changes the risk conversation. JetBrains’ earlier July advisory said the company was not aware of exploitation at that time; CISA’s newer KEV action now says there is evidence of active exploitation. CISA lists known ransomware use as unknown, not “no,” and gives U.S. civilian federal agencies an August 8 remediation due date.
JetBrains says all TeamCity On-Premises versions are affected. The fixed releases are 2025.11.7 and 2026.1.3. A security patch plugin is available for TeamCity 2017.1 and newer when a full upgrade cannot happen immediately. JetBrains says TeamCity Cloud customers require no action for this issue.
- Good: CISA’s KEV designation provides a clear exploitation signal, and JetBrains published fixed versions plus a patch path.
- Bad: unauthenticated code execution on a build server can turn a single exposed host into a broader software-supply-chain incident.
- Caution: patching closes the known hole; it does not prove an already-exposed server was never accessed.
Administrator action: inventory every TeamCity On-Premises instance, remove unnecessary internet exposure, upgrade or apply the approved patch, preserve application/proxy/agent logs, inspect unusual build and agent activity, rotate reachable credentials from a known-clean system, and validate recent artifacts before trusting or redeploying them. If you find encryption, extortion or suspicious mass file changes, start with The IT Guys’ first-15-minutes ransomware response checklist.
2. Researchers demonstrate real-IP leaks through WebKit and Private Relay
Researchers Talal Haj Bakry and Tommy Mysk documented three WebKit behaviors that they say can bypass application-level proxying. TechCrunch reports that it independently ran the proof of concept and saw its real IP address revealed.
The reported paths involve DNS prefetching, WebAuthn Related Origin Requests and WebTransport. DNS prefetch can expose information about the user’s resolver or network; the other two paths can reveal the device’s real IP address. Because Apple requires iOS browsers to use WebKit, the researchers say the weakness affects more than the visible Safari application.
The researchers say a full-device VPN is not affected in the same way because it tunnels traffic at the operating-system level rather than relying on a browser-level route. That is not a blanket endorsement of every VPN provider: the VPN operator can become a new party that sees traffic metadata, and account, DNS, browser-fingerprinting and application leaks still require separate thought.
- Good: independent reproduction moves this beyond a theoretical one-source claim.
- Bad: people may have treated Private Relay as stronger anonymity than Apple actually promises.
- Caution: do not install a random “privacy fix” from a pop-up, ad or unverified configuration profile.
Practical action: treat Private Relay as a privacy layer, not an anonymity guarantee. Users with elevated risk should minimize untrusted browsing, evaluate a reputable system-level VPN against their threat model, keep iOS and browsers current, and watch for Apple guidance. For the broader month-ahead update picture, use our August 2026 Windows and Apple update preview.
3. Jeff Dean and other senior Google AI researchers form Discovery Loop
Jeff Dean, Sanjay Ghemawat, Quoc Le and Oriol Vinyals are leaving Google to establish Discovery Loop, a public-benefit corporation focused on using artificial intelligence to automate scientific and engineering experimentation. TechCrunch reports that Alphabet is an investor and that Radical Ventures and Khosla Ventures co-led the initial financing.
The shift is important because competition is moving beyond general chatbots. Laboratories and engineering teams want systems that can propose experiments, operate instruments or simulations, analyze results, update hypotheses and preserve a traceable record. If it works reliably, that could accelerate materials, drug, electronics and industrial research.
- Good: experienced researchers are targeting measurable scientific workflows instead of only another consumer chat interface.
- Bad: an automated experiment can multiply a bad assumption, contaminated dataset or unsafe procedure faster than a human team.
- Reality check: a famous team and strong investors do not prove the product can produce reproducible discoveries at scale. TechCrunch says Dean reportedly plans to be CEO; we preserve that qualifier.
Business action: evaluate AI-for-science systems by reproducibility, source lineage, lab safety, access control, human approval, ownership of generated intellectual property and the ability to export the full experiment record. A dramatic demo is not a validated research process.
4. Anthropic confirms it is building a custom-silicon team
Anthropic confirmed to TechCrunch that it is building a custom-silicon team and wants to co-design hardware and models for faster, more efficient operation. The reporting cites a job listing for engineers with chip-design experience.
This is not a chip launch. The selected source does not provide a production design, delivery date or confirmed foundry arrangement. Anthropic currently depends on infrastructure relationships involving major cloud and chip providers; a custom design effort could give it more control over performance, cost and model architecture, but actual silicon programs are expensive and slow.
- Good: hardware/model co-design can improve performance per watt and create alternatives in a concentrated accelerator market.
- Bad: deeper vertical integration can also create new lock-in, migration costs and proprietary dependencies.
- Buyer caution: compare real workload latency, throughput, energy, availability, data controls and total cost—not a vendor’s theoretical peak number.
5. AMD’s data-center business powers a record quarter
AMD reported record second-quarter revenue of $11.536 billion, up 50% year over year. Its Data Center segment produced $6.7 billion, up 107%, driven by EPYC processors and Instinct accelerators. AMD guided third-quarter revenue to approximately $13 billion, plus or minus $300 million, with about a 56% non-GAAP gross margin.
The release arrived at 4:15 PM EDT on August 4—45 minutes before this recap’s strict rolling window—and is included transparently because it materially shaped August 5 industry coverage.
- Good: stronger competition in server CPUs and AI accelerators can improve buyer choice and pressure performance and pricing.
- Bad: rapidly growing AI infrastructure spending can still leave customers with scarce capacity, high power costs and immature workloads.
- Caution: the numbers are company-reported, and guidance is forward-looking. Revenue growth does not guarantee lower cloud or hardware bills.
IT planning action: benchmark your own workload, include energy and cooling, check software compatibility, price networking and storage, document supply and support terms, and retain a migration path. “AI-ready” is not a substitute for a measured requirement.
6. Shopify says AI referrals are growing alongside traditional search
Shopify says AI-referred traffic and orders tripled year over year in its second quarter while traditional search remained roughly one-third of storefront sessions. The company also said half of AI-referred sessions landed directly on product pages—2.5 times the rate for traditional search. Quarterly revenue rose 36% to $3.6 billion.
The practical takeaway is not “Google is dead.” On Shopify’s platform, AI discovery appears to be adding a fast-growing route to products while conventional search remains substantial.
- Good: a second discovery channel can bring shoppers closer to a relevant product page.
- Bad: agents and answer engines can repeat stale prices, obsolete stock, incomplete return terms or inaccurate product claims.
- Caution: platform-wide growth does not guarantee the same result for a small merchant, and attribution from AI tools can be incomplete.
Merchant action: keep product titles, descriptions, specifications, prices, inventory, shipping, returns and contact information accurate and machine-readable. Maintain fast mobile pages and conventional search work. Separate AI referrals in analytics, track qualified conversions rather than clicks alone, and never let an automated feed publish unsupported product claims.
7. Cloudflare adds identity analytics and previews write controls for AI agents
Cloudflare announced identity-aware analytics for AI Gateway and a private-beta control called WriteGuard for write-capable Model Context Protocol tools. Cloudflare says User Insights creates per-identity behavioral baselines from traffic already passing through AI Gateway, while WriteGuard is intended to apply policy, attribution and auditing when an agent attempts an action.
The security direction is sensible: a business needs to know which human identity sits behind an agent, which tool it used, what it changed, whether the behavior was unusual and how to reverse it. However, these are Cloudflare availability statements and product claims, not an independent benchmark. WriteGuard remains private beta.
- Good: separate identity and per-tool policy are better than one shared API key with broad write access.
- Bad: a correctly attributed agent can still follow malicious instructions, expose data or make an authorized-but-wrong change.
- Caution: logging after the fact does not replace prevention, approval and rollback.
Business rule: start read-only; issue unique identities; minimize data and tools; use short-lived credentials; require human approval for destructive, financial or public actions; retain meaningful logs; and test the kill switch plus rollback before increasing autonomy.
Windows and Apple watch
No same-day production Windows security or servicing release qualified for a separate headline before this edition closed. Use Windows Update and official vendor channels; do not install an alleged “August update” from a search ad or pop-up. The Apple item tonight is the independently reproduced Private Relay/WebKit privacy weakness—not an Apple-announced emergency patch and not evidence that every iPhone is compromised.
The IT Guys action list for tonight
- TeamCity administrators: find every On-Premises instance, restrict exposure, patch, preserve logs, rotate reachable secrets and verify recent builds.
- Privacy-sensitive users: know what Private Relay does not promise; watch for Apple guidance and evaluate a reputable full-device VPN only against a clear threat model.
- AI buyers: require reproducible results, separate identities, minimal tools, approval gates, action logs and tested rollback.
- Infrastructure buyers: benchmark real workloads and total cost instead of buying from peak-performance claims.
- Online merchants: keep conventional search and AI-discovery data accurate, current, fast and measurable.
- Account owners: if staffing changes, preserve Microsoft 365 or Google Workspace data before deleting an account; use our employee-data preservation guide.
- Catch up: read Tuesday’s recap for the ChainDrop npm worm, XCSSET Mac developer malware and Texas data-center audit.
FAQ
Is every TeamCity server already compromised?
No. CISA’s KEV listing means there is evidence of active exploitation, not that every instance was breached. An internet-exposed, unpatched On-Premises server deserves urgent patching and retrospective review. TeamCity Cloud customers do not need action for this specific flaw according to JetBrains.
If I patch TeamCity, is the incident over?
Not necessarily. Patching prevents exploitation through the known flaw but does not erase earlier access. Preserve logs, inspect agents and builds, rotate exposed secrets from a clean system and validate artifacts created during the exposure window.
Does iCloud Private Relay still help?
It can still reduce direct visibility by websites and network providers in ordinary Safari browsing, but the report shows it should not be treated as complete anonymity. Users with a serious threat model need layered controls and should watch for formal Apple guidance.
Should every iPhone user install a VPN tonight?
No. A VPN changes who can observe traffic and introduces provider trust, cost and configuration questions. People with elevated privacy needs should evaluate reputable providers and device-wide behavior; ordinary users should avoid panic downloads and keep software current.
Is Anthropic releasing a chip?
Not yet. It confirmed a custom-silicon team and co-design intention. The selected report does not provide a production chip, release date or final manufacturing plan.
Does Shopify’s report mean I can stop caring about Google search?
No. Shopify says traditional search still accounted for roughly one-third of sessions. Treat AI referrals as an additional channel: keep product data trustworthy, measure conversions, and maintain search, email, direct and local discovery.
Can identity-aware AI controls make an agent safe?
They improve attribution and policy enforcement, but no dashboard guarantees correct judgment. Limit authority, separate credentials, require approval for consequential writes, retain logs and prove rollback.
Sources checked
- CISA — CVE-2026-63077 added to the Known Exploited Vulnerabilities catalog
- JetBrains — TeamCity CVE-2026-63077 fixes and patch guidance
- TechCrunch — independent Private Relay/WebKit proof-of-concept reproduction
- Mysk research — WebKit proxy and iCloud Private Relay IP leaks
- TechCrunch — Discovery Loop founding team and financing
- TechCrunch — Anthropic custom-silicon team confirmation
- AMD Investor Relations — second-quarter 2026 financial results
- TechCrunch — Shopify AI-referral and search data
- Cloudflare — identity-aware AI Gateway analytics
- Cloudflare — WriteGuard private-beta announcement
Reporting note: Sources were checked through 5 PM EDT on August 5, 2026. Vendor claims and forward-looking statements are labeled. AMD’s release is explicitly disclosed as 45 minutes outside the strict rolling window. Practical implications are The IT Guys’ analysis.
