> daily_signal(2026_07_31)

Nvidia stood up an open AI-security alliance and shut the big closed labs out, the FTC accused Hims of leaking your health data, and North Korea turned a package inside your apps into a weapon.

PickBits Daily Signal · Friday, July 31, 2026

By Mark Pickering · 8 min read · July 31, 2026

// tl;dr

Two of these we have been following for weeks, and today they both moved. The open-versus-closed AI fight we have tracked since spring stopped being a debate and turned into a membership list, with Nvidia and thirty-six partners on one side and the three biggest closed labs conspicuously off it. And the npm supply-chain problem we have been covering came back with a name on it: North Korea, reaching a hundred million weekly downloads through one trusted maintainer.

The FTC story is the one to forward to anyone who has used a telehealth app. It says Hims spent years quietly turning the conditions people typed in, the private ones, into ad-targeting data for Meta and Snap. That is the same broken promise at the center of every health-data privacy fight. The last story is the good news, and it is real: a causal AI that may have found a survival gap in how the sickest ICU patients get treated. Its own authors call it a preprint, not a verdict, and I will hold it exactly that carefully.

Nvidia drew the open-versus-closed line as a membership list, and OpenAI, Anthropic, and Google are standing on the far side of it.

1. Nvidia built an open AI-security alliance and left the three biggest closed labs out.

Microsoft, IBM, Red Hat, CrowdStrike, and the Linux Foundation are in; OpenAI, Anthropic, and Google signed only a side letter.

On July 27, Nvidia and 36 partner organizations launched the Open Secure AI Alliance, a 37-member group whose stated job is to build open, shareable tools for securing AI systems. The roster reads like the enterprise-infrastructure phone book: Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation. The pointed absence is the three labs with the most capable closed models, OpenAI, Anthropic, and Google. OpenAI, Google, and Meta signed only an adjacent industry policy letter, and Anthropic joined nothing at all.

The stated rationale is blunt, and it is aimed at buyers: organizations should be able to inspect and self-host the models they depend on, not only reach them through a vendor's closed API. The alliance shipped its first deliverable alongside the announcement: NOOA, an Apache-2.0 framework Nvidia says scored 86.8% on a vulnerability-rediscovery benchmark. I will say the obvious thing too: Nvidia sells the hardware that self-hosted, open models run on, so "open is safer" is also "open is good for Nvidia." That does not make the move fake. Ignore the motive and the useful part still stands, which is that the vendors most enterprises already pay have taken a public side on open versus closed.

Screenshot of The Hacker News report on Nvidia forming the 37-member Open Secure AI Alliance
thehackernews.com · July 27, 2026

Why this matters: The vendors you already pay just declared, in public, which side of the open-versus-closed AI line they will build on, and the labs with the most capable closed models chose the other side. That split tells you something you can actually use. My read: a company that commits to open, self-hostable models is betting its customers will eventually demand to see how the AI reached a conclusion, and the closed labs are betting they never will. I think the open side is reading enterprises right, but you do not have to agree with me to use it, because the demo looks identical and the product underneath is not.

Action this week: The question I'd get answered before your next AI renewal is the plain one: can we inspect and self-host this model, or can we only reach it through your API? I'd hold NOOA up against whatever closed security assistant you run for one task where you actually need to see how a finding was produced, because being able to see that is the whole pitch, and it is cheap to test. And I would not read the alliance's roster as gospel; read it as a signal about who is planning for the audit and who is planning for the black box.

thehackernews.com: Nvidia forms 37-member Open Secure AI Alliance (July 27, 2026)
coindesk.com: Nvidia forms 37-member AI security alliance without OpenAI, Anthropic, or Google (July 27, 2026)
tomshardware.com: OpenAI, Google, and Anthropic absent from Nvidia-led Open Secure AI Alliance (July 2026)

2. The FTC says Hims fed the health data you typed in to Meta and Snap.

California and Utah joined the suit; Hims calls it unsupported, and its stock fell about 10% the same day.

On July 29, the FTC, joined by California and Utah, sued Hims & Hers in the Northern District of California, alleging the telehealth company shared customers' sensitive health information with advertising platforms including Meta and Snap while promising users their data stayed private. The mechanism the complaint describes is mundane and that is the point: Hims allegedly handed over customer lists carrying health-condition information, and let third-party tracking tags fire on-site so visitor actions, the "Events," flowed straight to those platforms.

The agency ties this to services people reach for quietly: weight loss, mental-health medications, sexual health. The complaint also alleges that Hims charged some customers for prescriptions almost immediately after an intake form, before a clinician had weighed in, and then made the subscription hard to cancel. Hims denies all of it, calling the suit unsupported after a nearly three-year investigation. Two things sit next to each other here: an allegation is not a finding, and the market did not wait for one, and the stock dropped about 10% the day the suit landed.

Screenshot of The Record's report on the FTC lawsuit against Hims & Hers over health data sharing
therecord.media · July 29, 2026

Why this matters: The intimate answers you typed into a Hims or Hers intake form, the weight-loss ones, the mental-health ones, are exactly what the FTC says got repackaged into ad audiences on Meta and Snap. That is a different fear than a breach. Nobody broke in; the allegation is that the company you trusted did it on purpose, through the same ordinary marketing pixels that sit on half the web, while the page in front of you said your information was private. Health apps have coasted on "we keep it private" as a marketing line for years, and now a regulator is dragging that line into court to find out whether it means anything.

Action this week: The two minutes I'd actually spend today are inside your own Meta and Snap settings, so turn off off-platform activity and ad personalization, because that is the exact plumbing the FTC says was used, and it works the same whether or not this suit does. When I've entered health details on a telehealth site since, I've opened it with tracker-blocking on first, just to see what fires on the intake page. And the thing worth following is the docket itself: a consent order here becomes the template every other health app gets measured against, which is where a resident actually has a lever.

therecord.media: FTC, states sue Hims & Hers over health-data privacy practices (July 29, 2026)
ftc.gov: FTC and states act against Hims & Hers over deceptive, unlawful privacy practices (July 2026)
techcrunch.com: FTC sues Hims & Hers for allegedly sharing patients' medical data with advertisers (July 30, 2026)

PickBits Daily Signal is free. If it lands in your inbox every day and it is worth something to you, the best way to support it is to forward it to someone who would read it. Subscribe today!

3. North Korea turned axios, a package inside millions of apps, into a weapon.

Amazon's threat team tied four npm compromises to the Sapphire Sleet crew, every one through a socially engineered maintainer.

On July 30, Amazon Threat Intelligence assessed with medium confidence that a financially motivated North Korean group it tracks as Sapphire Sleet was behind a string of npm supply-chain compromises: typo-crypto in March 2025, debug and chalk in September 2025, and axios in March 2026. Axios is not obscure. It is downloaded more than 100 million times a week and embedded in countless enterprise services. The same crew helped North Korea steal more than $2 billion in cryptocurrency in 2025.

The access method is the whole lesson. The attacker did not find a bug in axios; it socially engineered a trusted maintainer into publishing a malicious version, and let every organization that auto-pulled "latest" ship the compromise for it. That is why the blast radius is measured in propagation speed rather than sophistication: the earlier debug and chalk hijack is estimated to have reached about 10% of cloud environments within two hours of publication. This crew has done it before: Amazon ties the same group to the typo-crypto, debug, and chalk compromises that came before axios. At this point I care less about which package got hit and more about what keeps working: win over the person, not the code, and let everyone's CI do the spreading.

Screenshot of The Record's report on Amazon linking North Korean hackers to npm supply-chain attacks
therecord.media · July 30, 2026

Why this matters: Axios is almost certainly somewhere in your build right now, and the way it got compromised should reset how you think about "trusted" dependencies. The compromise rode in on a real maintainer's account, so the safeguards that assume danger lives in bad code missed it entirely, and your own automatic updates were the delivery truck. When the weakest link is a person and the distribution is your CI pipeline, "it's a popular package, it's fine" stops being a security argument.

Action this week: Start by auditing your dependency tree for axios, debug, and chalk and pinning them to the versions Amazon flagged, because "latest" is exactly what carried this. The one I'd put in writing, though, is a policy: no critical package auto-updates in CI without a signature or provenance check, so a poisoned release can't walk straight into production before a human looks. And I'd tell your developers plainly that a surprise maintainer change or a sudden new publisher on a package you depend on is now an incident trigger, not a footnote. That is the signal that would have caught every one of these.

therecord.media: North Korean hackers behind major open-source supply-chain attacks, Amazon says (July 30, 2026)
aws.amazon.com: Amazon identifies North Korean hacker group behind open-source supply-chain attacks (July 2026)

4. A causal AI flagged a survival gap in how the sickest ICU patients get treated.

When doctors' actual doses diverged from the model's recommendation, in-hospital mortality odds ran about 5.6 times higher, in a July preprint the authors themselves call early.

A July 2026 preprint on medRxiv describes a "causal AI" clinician that recommends vasopressor and fluid dosing in the first six hours of septic shock, the window where a body's runaway response to infection turns fatal fastest. Unlike a model that just pattern-matches, this one is built to reason about cause and effect. It was trained on 1,702 US MIMIC ICU admissions and externally validated on 1,434 US eICU admissions, 3,136 patients in all.

The number everyone will quote is the mortality gap. When clinicians' real-world vasopressor dosing diverged from the model's recommendation, in-hospital mortality odds were a median of about 5.6 times higher (odds ratio 5.61); diverging on fluids barely moved the needle. It stops short of proof, though, and the authors say so first: this is a preprint, not yet peer-reviewed, and the mortality figure is an association in retrospective records, not a demonstration that following the AI would have kept those patients alive. Sepsis is common in US hospitals and it moves fast, and dosing is still largely judgment, which is exactly why a signal this large is worth a real trial rather than a bedside rollout.

Screenshot of Yesil Science's summary of the causal-AI septic-shock dosing preprint
yesilscience.com · July 2026

Why this matters: The figure that stops me is the 5.6. Not because it proves the AI is right, but because it points a bright light at a survival gap in one of medicine's hardest, most time-pressured calls, and it does it with a model built to reason about the physiology rather than the correlations. This is the kind of medical AI I actually want to see: narrow, pointed at one decision that is still mostly gut feel under brutal time pressure, rather than a chatbot arguing with your doctor about everything. The caveat has to ride with the promise, though, and everyone serious about this says the same thing, that a number this big is a reason to run the trial, not a reason to skip it.

Action this week: What I'm watching is whether this gets to peer review and, more importantly, to a prospective trial, because that is the line between "correlated with better outcomes" and "safe to put near a patient." If you evaluate clinical decision-support tools, the question worth asking every vendor is whether their sepsis model is causal or purely correlational, and whether it was validated on a genuinely separate cohort the way this one was on eICU. And if you or someone you love lands in an ICU, the thing that helps most is older than any model: a complete, accurate history is the one input both the AI and the doctor actually need.

yesilscience.com: AI sepsis dosing recommendations match better survival outcomes (July 2026)
medrxiv.org: Causal-AI model for early haemodynamic management of septic shock (preprint, July 6, 2026)

» What to watch this week

Tomorrow's signal lands here.