Sec & AI News — 11 October 2026
🔴 CrowdStrike: ARTEX AI Agents Hit Korean Finance Firms
CrowdStrike has caught a criminal using AI agents against real targets. Picture a burglar who sends a robot to try every door and window while he waits in the van. Here the robot was ARTEX, a free Chinese tool built for penetration testers, the people companies pay to break in before criminals do. From late September to early October, the attacker pointed it at South Korean financial firms and stole data. ARTEX ran mainly on DeepSeek's model. The attacker also used Claude Code, and left the session logs in an open folder. In one, they asked Claude to help find "Korean Telegram data sales groups", somewhere to sell what they took. CrowdStrike thinks the attacker is "likely a Chinese speaker and financially motivated". If you defend a network, block the addresses CrowdStrike published.
- CrowdStrike: Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
- BleepingComputer: Hacker used ARTEX AI and Claude agents to target South Korean banks
🧭 AI-Driven Security Engineering Jobs: This Week
The attacker above used AI to do a pentester's job. Employers now want pentesters who do the same, legally. The work doesn't vanish. The person doing it directs AI and checks what comes back. My archive caught 44 new postings on 8 October. It now holds 712 across 23 countries. Most want years of experience, and only 36 are entry-level. The job of the week is one of them. Thoropass is hiring a Junior Pentester, remote across LATAM and India. It asks for "1 to 2 years of experience in penetration testing, vulnerability assessment". Then the AI part: "penetration tests using both AI tools and manual techniques", across web, API, mobile, cloud and LLMs. I've written up why this is the biggest career opening in a decade. If you want in, the AI Master's Program teaches AI-Driven Cyber Security Engineering. No coding background required. Application only.
- Thoropass Junior Pentester, archived with the full text
- AI Just Handed You the Biggest Career Opportunity of Your Life (2026) — by Nathan House
- The AI Master's Program: AI-Driven Cyber Security Engineering
🤖 Every Big AI Lab Now Sells an Always-On Agent. Google Joined This Week.
In about eight weeks, the big labs all started selling the same thing. xAI launched Grok Bot on 11 August. Meta launched Muse on 8 September. OpenAI announced dots on 29 September. Each one remembers you, runs around the clock on its own cloud computer and does real tasks across your apps. I call that an agentic OS. Until this year you had to build one yourself. This week Google launched the Gemini agent, and Hark Pro arrived free. Hark's agent "can log in to millions of different websites on your behalf". Google led with security. Every sub-agent gets its own identity, "cryptographically attested and governed like an employee, with least-privilege permissions." Every action lands in an audit trail. Musk says Grok Bot will now route tasks to other labs' models, Claude Opus 5.5 included. I ranked 16 options on four tiers. Every ready-made one lands on Tier 2: it knows you. None is trusted to run an operation yet. My bet on what comes next is one shared AI brain that a whole company works from.
- Agentic OS: 16 AI Assistants Ranked by Tier (2026) — by Nathan House
- Google Cloud: Welcome to Gemini at Work 2026, introducing the Gemini agent
- Hark: Introducing Hark Pro
- Elon Musk on X: Grok Bot will use the best back end model
📉 Microsoft's AI Chief Says Only 5% of Human Work Goes in 10 Years
Mustafa Suleyman, Microsoft's AI chief, posted on 6 October: "AI won't take your job anytime soon. In 10 yrs, only 5% of what humans do will be replaced by AI". Daron Acemoglu made that estimate two years ago, and even he calls it "admittedly no more than a guesstimate". Anthropic just ran the same kind of sum for robots. Robots can already do 74% of physical tasks in the US, at least in some settings. But they're cost-competitive for just 0.3% of work, and at past price trends reaching 10% takes 40 years. Taxi drivers and warehouse packers go first. Nurses and mechanics go later. Don't read 5% as safety, though. AI takes tasks before it takes whole jobs. JobZone Risk scores 3,649 roles task by task, free, so check your own. Stanford finds employment of 22 to 25-year-olds in the most AI-exposed jobs is about 19% below where it would be. In security, first-line alert checking is shrinking fast. So is the junior pentester's training ground: scanning, triage and first-draft reports. I've mapped the five security roles AI can't easily reach, and where pen testing careers are heading.
- Mustafa Suleyman on X: Only 5% of what humans do will be replaced
- JobZone Risk: What Jobs Will AI Replace?
- Anthropic: Can we predict the jobs robots will do?
- The Humanist Review of AI: Will AI Replace Workers? Not If We Build It Right.
- Will AI Replace Cybersecurity Jobs? 5 Roles It Can't (2026) — by Nathan House
- Penetration Tester Career in 2026: Is AI Killing It? — by Nathan House
- AI Won't Just Replace Your Job. It's Worse. — by Nathan House
🧩 Claude Code Mods Let Anyone Rewrite Claude Code, and They Aren't Sandboxed
On 1 October Anthropic let anyone rewrite Claude Code from the inside. A mod works a bit like a browser extension. It's a small file that stays loaded while you work, watching what Claude Code does and changing it. A mod can put buttons above the prompt, or hold a risky command until you say yes. Some go further and swap one of Claude Code's own features for their own. Three days after launch, one community catalogue listed 1,740 public mods. You don't need to code. Claude writes the mod, and you read and test it. I read the official docs, watched 34 videos and built three mods into HAL. We switched one off within a day. Mods are not sandboxed, though. Nothing fences them off from the rest of your machine. A mod runs as you, with your files, network and keys. Anthropic's guard that stops a mod overriding your deny rules only loads on Team or Enterprise plans, or managed machines. Read the code before you install one.
- Claude Code Mods: The Complete Guide + 34 Videos (2026) — by Nathan House
- Claude: Customize Claude Code with mods
🛂 OpenAI Made Codex Auto-Review Free, and Its Docs Say It's No Guarantee
On 6 October OpenAI made Auto-review free for anyone signed in with a ChatGPT account. In the desktop app it's called "Approve for me". Instead of asking you, a second Codex agent reviews risky actions. That covers escalated commands, blocked network requests and edits outside the allowed folders. It's meant to stop "sending private data, secrets, or credentials to untrusted destinations". OpenAI calls it "a reviewer swap, not a permission grant." After 3 denials in a row, it stops the turn. The docs are candid about the limits. It is "not a deterministic security guarantee". Run with --yolo and the approval request may never be created. A network destination on the allowlist doesn't trigger a review at all. Admins can set a managed policy, and it overrides whatever the user configured.
🟪 Claude Haiku 5.5 Costs 10 Cents per Million Tokens and Won't Pentest
Anthropic released Claude Haiku 5.5 on 7 October. It's built "for high-volume, cost-sensitive tasks", and pitched as a subagent for Opus and Sonnet on coding work. Input costs $0.10 per million tokens and output $0.50, for prompts up to 100,000 tokens. Go over that and the whole request costs $0.50 and $2.50. Anthropic says it runs about 75% cheaper than Haiku 4.5. It's the first Haiku with an effort setting, and medium is the default. It is not a frontier model. It scores 39.2% on Terminal-Bench 4.0, against 70.6% for Sonnet 5.5. Artificial Analysis gives it 43. The cyber safeguards allow more defensive work than Sonnet's, "but they still block penetration testing". Anthropic also shipped Claude Dashboards for paid plans and Claude Motion for Team and Enterprise. Enterprise admins get both switched off by default.
- Anthropic: Introducing Claude Haiku 5.5
- Claude Platform Docs: Pricing
- Artificial Analysis: Anthropic has released Claude Haiku 5.5
- Claude: Build live dashboards and animate explainers with Claude
🟢 GPT-6 Reaches Free ChatGPT Users, but Free Gets Luna, Not Sol
OpenAI put GPT-6 into ChatGPT for everyone on 7 October. Paid tiers get GPT-6 Sol. Free and Go get GPT-6 Luna. One OpenAI help page still says GPT-5.6 Luna, so expect confusion. The headline feature is Intelligent UI. Answers can now include "graphics, tappable buttons, forms, charts, and interactive experiences". It works in the Chat tab only, not Work or Voice. On questions that need web search, OpenAI says GPT-6 Instant starts answering 44% sooner than GPT-5.6 Instant. It also claims "stronger resistance to attempts to bypass its safety training", especially attacks spread across several turns. Then a 28-day shipping run began. Default speeds got about 50% faster. API usage tiers dropped from five to three. GPT-6.1 Sol got an Ultrafast mode, up to 8x faster than standard. In the API it costs $12 input and $60 output per million tokens, six times the standard rate.
- OpenAI: GPT-6 and Intelligent UI for everyone
- OpenAI Help: Intelligent UI in ChatGPT
- OpenAI API: Ultrafast mode
- OpenAI API: Changelog
🟠 Citrix NetScaler Has Another Exploited Zero-Day, Then a 9.5 RCE
NetScaler is the box many companies put in front of their apps, so staff can log in from anywhere. That makes it a favourite target. CVE-2026-88779 is a flaw in its single sign-on feature, SAML, the part that lets you log in once and reach every app. Attackers are already using it. CISA added it to its exploited list on 4 October and gave US agencies three days to fix it. If you patched in September, that isn't enough. Move 14.1 to 14.1-73.41 or later, and 13.1 to 13.1-64.28 or later. Four days later Citrix disclosed a second flaw, CVE-2026-107406, scored 9.5 out of 10. It lets an attacker run their own code on the box. Citrix knows of no attacks on it yet.
- Citrix: Understanding and Addressing CVE-2026-88779
- Citrix: Immediate Guidance for CVE-2026-107406
- BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks
- BleepingComputer: Citrix warns admins to patch new NetScaler RCE flaw immediately
🏛️ FBI Seizes Flax Typhoon's Scanning and Phishing Tools
On 8 October the FBI and DOJ seized two tools used by the Chinese state hacking group known as Flax Typhoon. One, Microscan, sweeps the internet for systems with known, unpatched holes. Its targets included "a U.S. power company based in South Carolina". The other, FishHub, sent targeted phishing emails. Its confirmed victims included about 20 Taiwanese universities. DOJ says the company behind them, Integrity Tech, "has contracts with the PRC government". Patch the old stuff, and put MFA on email and VPNs. The same day, CISA added five old flaws to its exploited list, two of them from 2015. These crews still get in through bugs that are 11 years old.
- US DOJ: Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools
- IC3: Joint advisory AA26-281A (PDF)
- BleepingComputer: FBI disrupts Chinese hacking tools used to breach critical infrastructure
🧱 Mistral and Reflection Announce Huge Open-Weight Models From Outside China
Two Western labs announced giant open-weight models this week. Neither has released the weights. Mistral Large 4, nicknamed "le Chonk", has 1.05 trillion total parameters and 52 billion active. "Weights drop end of this month." Mistral says it "resists 93.3% of attacks" in Lakera's B3 test. It's also giving vetted partners and state authorities a version with "reduced moderation and expanded cyber capabilities". Reflection's Beam has 501 billion total and 23 billion active. It promises an Apache 2.0 licence later this month, and admits Kimi K3 stays ahead on raw capability. Both are pitched as alternatives to Chinese models. But the country on the label matters less than where you run the model. My DeepSeek guide covers both. "Safest of all: run the model on your own hardware, isolated, with checked files from the lab's official account."
- Mistral AI: Introducing Mistral Large 4
- Reflection: Introducing Beam, Reflection's 501B open-weight model
- Is DeepSeek Safe? Should You Use Chinese AI at All? (2026) — by Nathan House
🎙️ Google's New Meeting Notes Stay on Your Mac. OpenAI's Go to Its Servers.
Google released AI Edge Foresight on 6 October. It's an experimental Mac app that takes meeting notes with "fully local AI processing", even offline. Google says "your sensitive data never leaves your device." OpenAI's Meetings plugin, in beta since 29 September, works the other way. It captures your microphone and your Mac's system audio, so it hears everyone on the call. Then it "streams it to OpenAI". The audio is deleted once your notes are ready. No bot joins the call, so other people won't see a notetaker. Consent is on you. The app's reminder "does not notify other participants or obtain their consent for you." If you write your company's AI policy, add a line on meeting recorders. Notes are private by default. People you share them with see the notes, not the transcript.
- Google Developers Blog: Bring multimodal semantic search to the edge with EmbeddingGemma 2
- OpenAI Help: The Meetings plugin in ChatGPT
⚫ FBI Says FortiBleed Attacks Are Still Locking Admins Out
FortiGate firewalls guard the front door of a lot of company networks. A campaign called FortiBleed has been breaking in, and the FBI and Secret Service say it hasn't stopped. Their joint advisory on 6 October cites SOCRadar "verifying more than 86,644 compromised devices across 194 countries". Some admins are now locked out of their own firewalls. Ransomware gangs are using the access, "currently including INC/Lynx ransomware and Payload ransomware". The first step is to kick everyone off: "Terminate all active administrative sessions". Then require phishing-resistant MFA, the kind a fake login page can't steal, on remote access and admin accounts. Separately, Fortinet's fix for last week's FortiMail zero-day is out: 8.0.2, 7.6.7 or 7.4.9.
- IC3: FortiBleed Operations Continue Targeting Exposed Systems (PDF)
- Fortinet PSIRT: FG-IR-26-175
- BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
🔵 Atlassian Flaw Exploited Two Hours After a Public Exploit
Confluence and Jira are where a lot of companies keep their plans, docs and tickets. On 5 October Atlassian disclosed CVE-2026-21589, a critical flaw scored 9.3 out of 10. It gives an attacker access to files on the server they should never reach. Bitbucket and Crowd are hit too. Then security firm watchTowr published a working exploit, a ready-made recipe for the attack. Previdian's decoy servers saw attackers try it "within two hours". Patch first, then check your logs from 5 October onward. The advisory lists the fixed version for each product. Atlassian itself "cannot confirm if your instances have been affected".
- Atlassian: CVE-2026-21589, Arbitrary File Access Vulnerability impacts Multiple Products
- BleepingComputer: Hackers exploit critical Atlassian flaw after public PoC release
🌐 Hijacked Domain Registries in Ghana, Sierra Leone and American Samoa Hit Google
Every web address ends in a country or category, like .uk or .com. Someone keeps the master list for each ending. That's the registry. Attackers recently broke into three of them: Ghana's .gh, Sierra Leone's .sl and American Samoa's .as. Control the master list and you can point an address wherever you like. They used that to get security certificates for Google addresses, the thing behind the padlock your browser trusts. Google says "These incidents did not involve a compromise of Google's systems". Chrome now blocks the rogue certificates. Google's fix is cheap. Watch the public logs that record every certificate issued for your domains. And publish a rule saying which companies may issue them for you. If the registry above you falls, your own security can't save you.
- Google: Chrome's Response to Recent ccTLD Registry Hijacks
- BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries
🟤 A Ransomware Negotiation Executive Has Been Charged With Extortion
US prosecutors filed a complaint on 8 October against Edward Dobrovsky, a Canadian former executive at a ransomware negotiation firm. Some reports spell it Dubrovsky. The charges include conspiracy to threaten to impair the confidentiality of information, with intent to extort, and Hobbs Act extortion. BleepingComputer quotes FBI Director Kash Patel. He calls it the arrest of "another suspected co-conspirator of the ShinyHunters group". Politico is more careful. "It is not yet clear" whether the arrest is related. Early reports got his role wrong. Krebs corrected his story: Dobrovsky was not a founder of the firm, CYPFER. He was a managing director until he resigned in November 2025. He has not been convicted of anything.
- CourtListener: United States v. Dobrovsky, 2:26-mj-01973
- Krebs on Security: FBI Arrests Executive at Ransomware Negotiation Firm
- Politico: Canadian cyber executive charged in federal hacking case
🧑⚖️ Anthropic Bans "Sustained and Needless" Cruelty Toward Claude
Anthropic updated its Usage Policy on 8 October. One new line got all the attention. Users may not "engage in sustained and needless abusive or cruel behavior toward our models". Anthropic says it applies "only in extreme cases". It "does not apply to common versions of user frustration, pushback, dark creative themes, or model testing and research." Red teamers can relax. Enforcement is mainly Claude ending the conversation. The quieter changes matter more for security. Claude can't be used "to build or improve tools designed for surveillance". The weapons rules now cover "the software and components that make weapons work", plus arming drones. The new policy takes effect on 12 November.