Business
Cloudflare open-sources vibe-coding platform for people who aren’t coders
Cloudflare’s CloudflareOS platform has been open-sourced. It was originally developed for internal use by employees, including those who were not engineers or software developers. Cloudflare also boasts of a framework for security that reduces the likelihood that employee sessions to vibe code could lead to serious security issues or data breaches.
Cloudflare spent months internally developing and testing Cloudflare’s OS. This platform allows users to create workflows using natural language, so an AI agent could code it into apps. Cloudflare claimed in a blog on August 5, announcing that the open-source version is now available on GitHub. The company said thousands of Cloudflare staff use it daily to “create slides and documents, automate repetitive tasks and build small applications to help them visualize data and do their work.”
In a blog post published on social media site X, Kenton Varda said, “This is a complete personal app vibe coding environment, where the sandbox can be so safe that the AI will not introduce a major security bug.” We believe that a company can give non-technical employees permission to code vibes and still sleep well at night.
Building better sandboxes
Varda explains that the security model is based on finely-grained instances of apps. For example, a document editing app will run each document in its own sandbox. Cloudflare OS manages access to each instance and allows each user their own code.
The sandboxing system, which is based on an existing Cloudflare function called Dynamic Workers does not use standard software containers. Instead, it creates “isolates”–instances of the V8 JavaScript execution engine–that take just a few milliseconds to start up and use only a few megabytes of memory. This makes isolated containers 100 times faster, and 10 to 100 times more efficient in terms of memory.
Cloudflare OS is a platform that allows AI agents to request permissions through Cloudflare. This helps minimize exposure of data. The server code is configured with global outbound networking turned off, while the client code operates in a “sandboxed browser frame.” This means that neither can access the Internet unless you provide it explicitly.
Cloudflare’s sandboxing process and the permissions it provides could be useful in real life, although no system can guarantee 100% security. Researchers from Pillar Security have just released a new report that details sandbox bypasses and boundary escapes found in AI agents like Cursor CLI and Antigravity.
Make the vibe code less sloppy
Cloudflare OS is compatible with any AI model, allowing organizations to choose the best model for their needs. Sam Rhea said in an additional blog that not every user needed access to max thinking mode, the latest Frontier Lab model. We don’t need to pay $20 for team members to sum up their inboxes every hour.
Rhea added that the company also enhanced its platform to run skill files in specific workflows using deterministic steps and AI inference only as needed, rather than needing a token-hungry session each time.
Administrators can also monitor employee AI spending, set rate and budget limits and track their employees’ AI usage. This is a vital feature in a world where companies and individuals are finding it all too easy for them to blow through budgets on AI models. This won’t prevent more questionable practice if leaders choose to encourage AI “tokenmaxxing”, to force employees to use AI.
Cloudflare has shared the hard lessons it learned as they tried to make AI tools more efficient through Cloudflare OS. Rhea revealed that one early mistake was to give everyone “the same tools” with “slightly friendlier user interfaces”, because AI code harnesses used by engineers are not suitable for work that involves “one-off results and projects involving dozens of system of records,” Rhea said.
Rhea said in his blog that if you gave everyone an environment where they can write code well, there would be way too much code. The result was a flood of apps that were coded in vibe and looking to solve a specific problem.
Rhea stated that the growing usage of AI agents in Cloudflare meant that “anyone could write bad code faster thanks to AI.” The Cloudflare Engineering Codex was created as a “reliable guide” for both AI and human engineers to review code.
In the last four months, Cloudflare’s AI code-reviewer has “flagged almost a quarter million deviations from Cloudflare Engineering Standards and blocked 16,000 mergers,” Timo Reimann said in a post on the Engineering Codex, and the way the company employs AI agents to enforce engineering standards.
Costs of open source software
Developers can now run Cloudflare OS on their machines, as the software is available for other users to download. Cloudflare’s Workers Paid users can deploy the Cloudflare backend.
It was initially not made obvious that a paid subscription would be required. The issue was raised by a GitHub user who shared a screenshot that showed their Workers Free plan being stopped mid-process from deploying Cloudflare’s OS backend.
The GitHub user, mac2net wrote: “You are entitled to charge for your services but you should complete the requirements before beginning the deployment process.” “I lost 20 minutes that I’ll never be able to get back.”
Cloudflare deserves credit for updating the process quickly to inform users about paid plans at the beginning. An official from the company responded on GitHub.
Business
Whole Foods recalls foods in 12 states over salmonella risk
Whole Foods announced on Wednesday it was recalling some produce and foods prepared with fresh jalapenos provided by Coast Citrus Distributors due to possible salmonella contamination.
Food and Drug Administration stated that the products with “Best Before” date ranges from August 7 to 16 were sold across 12 states.
According to FDA, no illnesses were reported as a result of the Whole Foods recall.
Whole Foods announced that the recall covers select salsas and prepared food, including guacamole. The FDA website has a complete list of the affected products.
As the JALAPENO SALMONELLA outbreak sickens 345, 18 PREPARED FOODS ARE UNDER ALERT.
These products are sold in Texas and Oklahoma as well as Louisiana, Wisconsin, Michigan Illinois, Iowa Missouri, Arkansas Indiana Kentucky, Ohio, Wisconsin.
Whole Foods’ spokesperson stated that the recall on Wednesday was due to jalapenos in the product, which were purchased from Coast Citrus Distributors. The products are also linked with the recall of the distributor. Taylor Fresh Foods announced a recall on Sunday that included some of the same products.
Whole Foods’ action coincides with a larger salmonella outbreak that is linked to jalapenos and has hospitalized 345 individuals in 27 states.
Before Whole Foods’ announcement, a USDA alert on public health in Sinaloa (Mexico) had identified at least 18 meat and poultry ready to eat products distributed by Coast Citrus Distributors.
Nearly 30,000 pounds of RAW beef were recalled due to a missed import inspection
Taylor Farms announced on Monday a voluntary recall of jalapenos-containing prepared foods sold in Walmart, Whole Foods and other retailers across several states due to possible salmonella contamination.
The FDA reminded consumers to return any recalled Whole Foods product they purchased or to bring their receipts to Whole Foods Market for a refund.
Federal regulators say that illnesses associated with the jalapeno epidemic began between 2026 and June 19.
A CULT FAVORITE PIZZA CHAIN USES A SURPRISING METHOD TO REPRODUCE NYC FLAVOR NATIONALLY
The outbreak has affected several large brands and retailers, such as Taylor Farms and Deli Kitchen. It also affects Marketside, Wawa and Albertsons.
According to officials, Chipotle Mexican Grill and QDOBA received the same jalapenos from Sinaloa.
Chipotle has switched their jalapeno suppliers at the affected restaurants beginning July 20, and will no longer serve this product. QDOBA, meanwhile, stopped serving jalapenos in all its locations as of July 28,
CLICK HERE TO GET FOX BUSINESS ON THE GO
Coast Citrus Distributors agreed to recall all remaining product implicated in the outbreak and will no longer import jalapenos produced by the linked grower.
Salmonellosis is caused by food contaminated with the salmonella bacteria. Symptoms include diarrhea, abdominal cramps, and fever.
Business
Ford boosts US Lincoln production as it phases out imports from China
Ford Motor Company has plans to increase U.S. Lincoln production beginning in 2030, and stop eventually importing cars from China for its American luxury customers.
Dearborn-based Ford said that this expansion will generate direct and indirect jobs in the United States for thousands. Ford has not disclosed how much money it intends to invest, or which plants will receive additional production.
This would be a major shift in Lincoln’s U.S. line-up, which includes currently the Nautilus built in China.
The Nautilus re-designed is built at Changan Ford’s plant in Hangzhou (China) and exported to America. Ford Oakville Assembly Plant, Ontario, Canada produced the previous generation.
Regulators warn that some older Ford vehicles pose ‘unreasonable’ safety risks.
Ford has not stated whether the Nautilus will be produced in the U.S. as part of its 2030 plan, or which China imported vehicles may be affected.
Ford, and other automakers in general, continue to face higher costs as well as uncertainty due to rising tariffs and shifting global trade policies.
Ford’s most recent annual report shows that tariffs implemented in 2025 will cost the company approximately $3 billion gross, and have an impact of approximately $2 billion on its earnings, before taxes, interest, and offsets.
Ford has not said whether trade concerns or tariffs were a factor in the decision to stop importing Lincolns from China.
Ford to Use Apple Maps Software in Self-Driving Technology for New EV Platform
Lincoln produces several vehicles in the United States. The Navigator, for example, is built at Ford’s Kentucky Truck Plant, located in Louisville. Meanwhile, the Aviator, which is manufactured at the Chicago Assembly Plant, is also produced by Lincoln. The vehicles are exported to Canada, Mexico, and the Middle East.
Ford will expand its already large U.S. production footprint with the additional production. Ford said that it would assemble more than two million cars in the U.S. by 2025. This is more than any other carmaker. It also leads the auto industry for U.S. vehicle imports and autoworker hourly employment.
Ford reports that it employs 56,300 manufacturing employees in the U.S.
Ticker Changes Last Change % FORD MOTOR COMPANY 13.83 +0.15 -1.07
CLICK HERE TO GET FOX BUSINESS ON THE GO
Ford has not revealed many details about its expansion plan for 2030, such as which models it will produce domestically, the location of that production, and how much money Ford intends to invest.
Business
Kroger closes at least 3 dozen stores across 9 grocery banners
Kroger closed more than 30 stores after announcing last year that it would close 60 outlets by 2026 if they did not deliver “sustainable results”.
Cincinnati’s grocery giant didn’t release an official list of all stores and banners that were to be closed, but searches on the internet revealed 39 sites across nine different banners no longer in operation. Local news reports confirmed that the majority of these locations are part of a larger store revamp.
According to a Securities and Exchange Commission (SEC) filing, as of January 2026 Kroger operated 2,697 grocery stores across 35 states, under approximately 20 different banners. These included Fred Meyer, Fry’s Food and Drugs, Harris Teeter and Jay C. Other brands include King Soopers and Mariano’s.
According to FOX26 Houston, the company stated that the closures were intended to “run our business more efficiently” and to ensure its long-term success. Two Houston area locations are scheduled to close by April.
In a $1.65 billion deal, KROGER will buy a popular grocery and pharmacy retailer.
Kroger, the national grocery retailer, announced last month that it would acquire Giant Eagle, a regional supermarket chain, for $1.65 Billion. This acquisition will add 197 additional stores and 11 independent pharmacies in northern Ohio, Western Pennsylvania, West Virginia and Indiana.
This acquisition will strengthen Kroger’s position in several Midwestern markets and Mid-Atlantic regions.
As part of Kroger’s consolidation efforts, at least three impacted stores were replaced or will be by Kroger Marketplaces. Kroger Marketplace is a larger format store that offers a wider selection of merchandise other than groceries, such as clothing, furniture, toys and homewares.
These locations are affected:
Kroger
Atlanta, Georgia — 2452 Morosgo Way NE
Brookhaven Georgia — 3855 Buford Highway NE
Decatur, Georgia – 3479 Memorial Dr.
Alpharetta, Georgia — 11877 Douglas Rd.
Peoria, Illinois — 3311 N Sterling Ave.
South Bend (Indiana) — 4526 West Western Ave.
Elkhart, Indiana — 901 Johnson St.
Louisville, Kentucky — 4211 S 3rd St.
Bossier City, Louisiana — 4100 Barksdale Blvd
Kingsport Tennessee — 1664 E Stone Dr.
Houston Texas – 239 West 20th St.
Houston, Texas — 9325 Katy Fwy.
Houston, Texas — 2300 Gessner Rd.
McKinney (Texas) — 2901 Lake Forest Drive
Spring, Texas — Farm to Market 6060 2920
Charlottesville, Virginia — 1904 Emmet St. N
Abingdon, Virginia — 466 Cummings St.
Gassaway West Virginia — 2908 State St.
South Charleston, West Virginia – 5 River Walk Mall (3060 Ray Park Boulevard) (consolidated in June last year into the new Kroger Marketplace).
Dunbar, West Virginia – 981 Dunbar Village
SEPHORA JOINS WALMART, TARGET WITH NEW ‘QUIET HOURS’ SHOPPING EXPERIENCE
Fred Meyer
Tacoma (Washington) — 7250 Pacific Ave.
Fry’s Food and Drug
Mesa, Arizona — 1915 S Power Rd.
Harris Teeter
Arlington, Virginia — 950 S George Mason Dr.
Arlington, Virginia – 3600 S Glebe Rd. W100
McLean, Virginia — 8200 Crestwood Heights Dr.
Rockville, Maryland – 11845 Old Georgetown Rd.
Raleigh, North Carolina — 5563 Western Blvd., Suite 6A
Charlotte, North Carolina — 5706 Wyalong Dr.
Ticker Security Changed Last % KR KROGER 56.06 +0.19 –0.34%
Jay C Food Stores
Shoals, Indiana – 201 High St.
King Soopers
Centennial, Colorado — 5050 E Arapahoe Rd.
Mariano’s
Buffalo Grove, Illinois — 450 W Half Day Rd.
Northbrook, Illinois — 2323 Capital Dr.
Bloomingdale Illinois — 144 S Gary Ave.
Choose & Save
Glendale Wisconsin – 1735 West Silver Spring Dr.
Milwaukee, Wisconsin — 3701 S 27th St.
Milwaukee, Wisconsin — 2355 N 35th St.
Oak Creek, Wisconsin — 2320 W Ryan Rd.
South Milwaukee, Wisconsin — 2931 S Chicago Ave.
QFC
Mill Creek — 926 164th St. SE
CLICK HERE TO GET FOX BUSINESS ON THE GO
FOX Business contacted Kroger to get more information.
Business
Bill Gates’ Daughter Knew For Months That Her App Claimed Sales It Didn’t Drive, Report Claims
Bloomberg published an investigation last month that claimed Phia was a startup founded by Phoebe Gates, daughter of billionaire Microsoft founder Bill Gates, and Sophia Kianni who is her Stanford roommate. They were engaging in unethical online practices.
According to the report, the web extension of this startup, which claims it can find better deals and discounts for online shoppers via cookie stuffing (which is against digital platform policies), had falsely claimed sales that were not generated.
It makes money from the retailers who pay it a commission for each sale it facilitates. To verify this, it drops a cookie in the browser of every shopper when they make a purchase that involves its extension. Bloomberg, Ben Edelman and Capital One Shopping, a rival company, claim to have conducted independent testing that found Phia’s app opens an unnoticed background tab in order to insert its affiliate code. This overrides other referrals so as to receive the commission. PayPal’s Honey was also accused of similar accusations in 2024. This led to a lawsuit filed by a group.
Phia’s representatives described the bug as such on July 8, telling Bloomberg the problem was only discovered “within 24 hours”. But a Bloomberg investigation has found that Phia executives and in particular Phoebe Gates were aware of this situation for at least 7 months prior to the publication of that report. They also actively encouraged the addition of these features.
Bloomberg reports that this issue is not a bug, but a controllable internal feature called “enable coupons auto drop”. Bloomberg cites anonymous Slack sources and internal Slack conversations to claim that Gates was in a Slack discussion with staffers back in December, and wanted to confirm that Phia dropped cookies across all websites even if a shopper didn’t use their coupon.
Reports also claim that Phia used other controversial practices. One feature included dropping cookies automatically every 2 hours for users who had interacted with Phia’s extension when visiting a “top 1000 websites.”
According to the internal communications presented by Bloomberg, an engineer tried telling co-founder Kianni that the practice could be “against compliance,” but Kianni allegedly responded with a Slack message saying: “I guess we could say that the user is trying to open us and roll it back if they complain.” Bloomberg reported that an engineer had tried to warn co-founder Kianni about the potential for the practice to be “against the law.” Kianni responded by sending a Slack chat message saying, “I suppose we could say the user was trying to open us, and roll it all back if the complainant.”
Kianni then responded with, “That’s great yeah whatever you can do to make these cookies keep falling will be awesome thank you.”
According to the report, after “coupon automatic drop” was disabled, Phia’s revenues plummeted from $80,000 down to $10,000-$28,000. This is based on an internal revenue chart.
Phia has denied all allegations made by Bloomberg. They also claimed that their revenue drop last month is solely the result of the reversed cookie stuffing. The company also hired a compliance head “to ensure that something similar never occurs again.”
Business
Some Claude users are mad that Anthropic’s new watermarks will catch them using it at their jobs, classes
The company has decided to add a watermark (invisible code) into the text of the bot’s chatbot, which marks the output as AI generated.
This new policy was implemented by Anthropic to comply with the EU AI Act Transparency Code. The code requires that tech companies label AI-generated content or edits in a way computer systems can identify. While European regulators are happy with the new policy, AI users may not be.
Reddit is a great place to see the growing discontent. However, other users on the website aren’t in agreement. A user called visionode posted a post that was incredibly dramatic. His account has only been active for three weeks. Visionode claims that the watermarking scheme is an evil conspiracy to harm innocent chatbot users around the world.
Visionode appears to believe that while savvy Claude-users may be able to hide their AI usage through paraphrasing and other AI cleaning services, average Claude users will get caught.
Who will be caught? You. You. The journalist that asked the AI for a summary of a 200-page transcript. Writer who was stuck for words and requested synonyms. They come out with digital tattoos on their foreheads.”
It would be wrong of me to minimize visionode’s outrage. But those examples aren’t the most effective. If a journalist asks AI to sum up a 200-page transcript, they won’t care if there is a watermark on the summary unless that person copies and pastes it verbatim in their article. That is unethical.
The same is true for a student that copies and pastes Claude’s work into an essay, after having asked it to “reorganize a sentence.”
Redditors did not support the outrage of this poster.
One poster simply commented, “Get your hands on this guy.”
One person asked another to “take a deep breath”.
Visionode was not the only person to complain. One unhappy customer called the watermarks ‘unethical’ and a scumbag. They also claimed that Claude had already done most of the hard work. According to them, Claude was just a tool that aided their laborious work.
I gave the instructions and context. Claude did the rest. The poster asked: “If Claude watermarks the code, or any other thing it produces, for what is it claiming to be responsible?”
The critic was slammed by other users.
One user replied, “It isn’t claiming any credit.” It’s all about detecting AI-generated outputs due to the potential risks AI-generated outputs may cause.
Another joked, “Bro could not even write a complaint about Claude if Claude was not used to do it.”
Some critics avoided the narrative of victimhood and used slightly nuanced arguments to oppose Anthropic’s new policy.
One poster, for example, complained about the hypocrisy of watermarking a product editorial that had been created by stealing other people’s ideas. The user said, “I find it a sinister move.” I don’t write with Claude, but an AI watermarking your work seems a bit ironic considering how the Frontier models got their data.
-
Business2 weeks agoMinnesota bans crypto ATMs after elderly population was targeted
-
Business5 days agoElon Musk plans 100 million-square-foot terafab semiconductor plant near Houston
-
Business3 days agoVandalized fiber lines cause Verizon service outage for thousands of SoCal customers
-
Entertainment2 weeks agoBrand New Day’ Post Credits Scene, Explained
-
Business1 week ago
Why extreme heat can force airlines to leave passengers behind
-
Business5 days agoHealth department investigating after seeing more than 5x increase in cyclosporiasis cases in McHenry County
-
BBC News World1 week agoSee the Sun like never before with most detailed images yet
-
BBC News World1 week agoHuman remains exhumed at site of controversial World War II massacres in Ukraine: “Each of them had their dreams”
