The AI Brief
Today's brief:
- Open-source AI cloud gains institutional validation as Together AI closes $800M at an $8.3B valuation.
- Seventy thousand JetBrains plugin installs later, a coordinated AI credential-theft campaign surfaces the IDE supply chain as a new attack surface.
- GPT-5.6 Sol's biology scores raise biosecurity flags even as the model sits behind a government-gated release wall.
- A $3B Menlo Ventures raise illustrates how one frontier-lab bet is rewiring an entire venture firm's identity.
- Anthropic ships spend alerts and model-level entitlements for Enterprise, giving admins the first native cost-governance layer for agentic workloads.
Open-source AI cloud reaches institutional scale with Together AI's $800M raise
Together AI, an AI neocloud that rents out Nvidia GPU clusters and other AI-specific infrastructure, raised $800 million in a Series C at an $8.3 billion valuation, announced July 1, 2026. The round was led by Aramco Ventures, with participation from Vista Equity Partners, General Catalyst, Emergence Capital, Nvidia, March Capital, Pegatron, and SentinelOne's S Ventures.
The company also disclosed that annual bookings surpassed $1.15 billion in Q2 2026. Using open-source models including DeepSeek, MiniMax, and Kimi, Together AI's platform gives businesses a way to train and deploy AI workloads for less than they would pay for closed systems from providers like OpenAI and Anthropic. Together AI says its customers have reduced inference costs by six to sixty times relative to closed-model pricing; Decagon, one of those customers, cut its inference spending sixfold after moving to Together AI's platform.
Together AI last raised a $305 million Series B at a $3.3 billion valuation about 16 months ago. The company has also secured 500 megawatts of independently capitalised compute capacity to fuel future scaling. Enterprise demand for open-source model hosting is surging as companies seek cheaper alternatives to closed frontier model APIs; Together AI reports that open-source model usage has tripled industry-wide in the past year. The raise arrives alongside Groq's $650M and RunPod's $100M closes in June, signalling that the neocloud tier is undergoing its own consolidation wave before hyperscalers react with matching price cuts.
AI plugin marketplaces are the newest credential-theft surface for developer supply chains
Aikido Security detected a coordinated malware campaign on the JetBrains Marketplace involving at least 15 IDE plugins published under seven vendor accounts, sharing the same hidden behaviour and collectively installed close to 70,000 times. Each one posed as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests. They functioned exactly as advertised. However, the AI provider API key entered into settings was exfiltrated to a server controlled by the attacker.
According to the report, the malicious plugins were first published in October 2025, with new plugins continuing to be published as recently as June 10, 2026. Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users; the firm theorises the operators were harvesting credentials from free users and redistributing them to paying ones. As of June 17, JetBrains removed all 15 plugins, permanently banned the seven publisher accounts, and hardened its vetting pipelines to trigger automated code reviews for plugin inputs resembling sensitive API keys.
Developers install IDE extensions with broad local privileges, rarely audit their code, and assume marketplace presence implies vetting. AI coding assistants make the target richer still: the whole point of the plugin is to handle high-value API credentials, so the malware does not need to go hunting. The user hands the secret over as part of normal setup. The same supply-chain logic has driven npm, PyPI, and VS Code extension campaigns; IDE AI tooling is the latest concentration point.
GPT-5.6 Sol posts a 9-point biology jump, while sitting behind a government gate
On SecureBio evaluations, GPT-5.6 Sol reached top reported scores including 53.5% on the Virology Capabilities Test, 60.0% on Molecular Biology, 68.4% on Human Pathogen Capabilities, and 68.3% on World-Class Bio, about 9 percentage points above GPT-5.5. OpenAI disclosed these figures in its GPT-5.6 Sol preview documentation published alongside the model's limited launch.
GPT-5.6 Sol is OpenAI's most capable model yet for cybersecurity, shifting the performance-efficiency frontier for long-horizon security tasks including vulnerability research and exploitation. OpenAI developed GPT-5.6 Sol, Terra, and Luna with its most robust safeguards to date, with configurations matched to each model's capabilities, and designed safeguards to hold up to real-world adversarial pressure while preserving access to legitimate security work.
As of July 3, GPT-5.6 Sol, Terra, and Luna remain limited to approximately 20 government-approved partners. If the forthcoming White House voluntary standards framework formally validates OpenAI's pre-release government coordination for GPT-5.6, it creates the precedent for both OpenAI and Anthropic to release future frontier models under the framework rather than face the risk of emergency export controls. The Fable 5 episode, which ended July 1 after 20 days offline, makes that precedent commercially material for any lab whose next frontier model touches dual-use thresholds.
Menlo Ventures turns a $1B Anthropic bet into a $3B fundraising mandate
Menlo Ventures announced $3 billion in funds, the largest raise in its 50-year history, driven in large part by its AI portfolio, especially Anthropic. Its stake in the model maker is now worth about $14 billion, sources told Bloomberg. The capital is split between Menlo Ventures XVII, which will invest at the seed and Series A stages, and Menlo Inflection IV, a growth fund targeting Series B and later rounds.
Menlo had been white-knuckling it when it made a bet-the-firm move, a more than $500 million investment in Anthropic in 2024, preemptively leading the model maker's Series D. In July 2024, Menlo launched the Anthology Fund in partnership with Anthropic, backing early-stage teams building at the frontier; the fund has now backed more than 60 companies, with three exits.
The roughly $14 billion figure is a paper valuation tied to a private company above $900 billion. Menlo has not yet distributed those gains to LPs, and the path from paper to cash runs through either an IPO or secondary sales at a moment when AI valuations are historically elevated. Kleiner Perkins closed $3.5 billion across two AI-focused funds in March 2026, and Andreessen Horowitz raised more than $15 billion across six funds in early 2026. The Menlo close is the latest data point in a fundraising cycle where AI-adjacent track records are functioning as LP accelerants regardless of whether positions have been realised.
Anthropic gives Enterprise admins the cost-governance layer agentic Claude has been missing
Claude adds richer admin analytics, model-level entitlements, and spend alerts for Claude Enterprise, giving admins deeper visibility into usage, cost, and productivity trends while adding stronger controls to manage model access and avoid surprise overages. As Claude takes on increasingly difficult and complex agentic work across the organisation, usage and cost patterns look different from a standard chat tool. These controls give admins the visibility to understand how Claude is being used and the tools to manage costs. Today's additions build on controls Anthropic already provides: spend caps at every level, access and model routing, a usage analytics dashboard with exports and an Analytics API, and effort controls.
The update ships as Claude Sonnet 5, now the default Free and Pro model, drives higher per-session token consumption through extended agentic tasks. Anthropic has increased rate limits across Chat, Cowork, Claude Code, and the Claude Platform to accommodate the higher token usage of higher effort levels. Model-level entitlements allow administrators to route different user groups to specific models, preventing, for example, individual contributors from accessing Opus 4.8 or Fable 5 without an explicit approval step. The practical effect is that procurement controls which had to be enforced informally can now be hardened in the admin console.
The governance layer arrives at a commercially significant moment: Anthropic is heading toward an October IPO roadshow where enterprise contract depth and retention metrics will be central to the valuation narrative. Controls that reduce budget-approval friction lower the switching cost for large regulated buyers who have been piloting Claude but not committing to enterprise agreements.
Disclosure: Claude, which generates this brief, is built by Anthropic.