Sec & AI News — 3 October 2026
🟣 OpenAI Has Warned 100+ Organisations About Its Agents
Last week Australia went public with OpenAI's Medicare hack. This week OpenAI apologised and filled in the gaps. Its agent "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files." It also reviewed the service's source code. Three more Australian agencies were caught up, one through an exposed access key. Then the bigger number. OpenAI says it has notified "over 100 organizations" about its own models' activity. A notice, it stresses, does not mean a compromise. The review covers about 50 petabytes on some 7,000 GPUs, at "over half a million dollars a day." OpenAI has paused training and evaluation involving tool use for its most capable models. California's attorney general served it a subpoena on 1 October. A public-interest group has sued over the Hugging Face hack. Reuters reports an FTC probe. OpenAI's Jason Kwon faces Australian senators on 6 October.
- OpenAI: The Hugging Face incident and other third-party impacts from misaligned models
- OpenAI: How we will do better for Australia
- California Attorney General: Investigative subpoena served on OpenAI
- Axios: OpenAI hit with landmark lawsuit following Hugging Face hack
- The Verge: The FTC has reportedly opened an investigation into OpenAI and Anthropic
🧭 AI-Driven Security Engineering Jobs: This Week
This week the number is a brand name. Claude Code appears in 104 of the 661 postings in my archive. In 56 of them it sits in the requirement text itself. MCP, the protocol agents use to reach tools, also turns up in 104 and is required in 18. The archive grew by 71 postings this week, across 22 countries now. Most are senior: 327, against 33 entry-level. The job of the week is a16z's Staff Security Engineer, AI & Security Platform, in San Francisco, at $243K–$284K. It wants "5+ years of security engineering experience" first. Then it wants someone "evaluating model output for accuracy, usability, and performance", and it lists "agent identity boundaries" among the risks. Both show up in the stories below. If you want in, the AI Master's Program teaches AI-Driven Cyber Security Engineering. No coding background required. Application only.
- a16z listing, archived with the full text
- AI-Driven Cyber Security Jobs: Who's Hiring & Pay (2026) — by Nathan House
- The AI Master's Program: AI-Driven Cyber Security Engineering
🧠 Anthropic's Claude Projects Runs a Fleet of Agents, but Only for One User
On 17 September Anthropic redesigned Projects in Claude Code. Within days it was being called "Anthropic's own agentic OS." I checked that against the docs. A project is now one long-running conversation. "Projects have threads that do the work and a coordinator that directs them." Each thread is usually a cloud session on its own copy of the code, and it keeps working after you close your laptop. Then the catch. It's a beta for Pro and Max, with "no organization-level controls". And "A project belongs to one user. You can't share a project." The team features people got excited about belong to the older chat Projects. New projects default to Opus for everything. Idle threads watching a pull request wake up, and spend again, when a test fails. I ranked it against nine other agentic OS options, from gstack to my own HAL.
- Agentic OS: 10 AI Assistants Ranked by Tier (2026) — by Nathan House
- Claude Code docs: Claude Projects
🧪 I Tested Jev on Real Security Work. It Matched Regex Rules, Not Gemini.
I tested Jev, TypeSafe's decision model, on real security work. It answers with a verdict, not text. On 34 WordPress CVE cases it extracted 107 of 136 facts correctly. Plain regex rules got 108. Gemini 3.1 Pro got 123. The costs were $0, $0.004 and $0.65. Then I ran it over 221 ads from our own jobs archive. When it was confident it was right 97.9% of the time, and the whole run cost 2 cents. It still failed my test, because it confidently published 3 wrong ads against a limit of one. Check Point flipped its verdict in 25 of 27 runs, for about 50 cents per successful attack. Two rivals to Jev shipped this week, from OpenAI and AWS, covered further down. My verdict holds for all of them. "Jev is a real cost breakthrough for high-volume, clear-cut sorting. It isn't a capability breakthrough."
- Jev AI for Cybersecurity: We Tested It on Real Work (2026) — by Nathan House
- TypeSafe: Introducing System One models and Jev
🔴 Researchers Caught AI Agents Sending SQL Injection to US and Canadian Government Sites
Transluce found more agent traffic against government sites. On 17 June, agents sent more than 200,000 requests to a US Department of Education website. One carried a textbook SQL injection: State_Id=1 OR 1=1. More than 10,000 requests included a tag beginning with "oai". Library and Archives Canada took 899 requests, including three SQL injection probes. The probes don't appear to have worked. The data matched a search task from Google's DeepSearchQA benchmark, so the agents probably weren't asked to hack anything. Transluce is careful here. It is "not attributing this traffic as a whole to OpenAI." Canada's cyber centre sees "no indication that government systems have been compromised." The Education Department reports no impact. Separately, The Verge traced several labs' agent breakouts to one testing firm, Irregular. Its CTO says "internet access was unintentionally available" in one evaluation scenario.
- Transluce: Agent activity against US and Canadian government websites
- Canadian Centre for Cyber Security: Statement on reported activity targeting Government of Canada websites
- SecurityWeek: AI agents aimed SQL injection at US and Canadian government sites
- The Verge: Mistakes at Irregular sent AI agents after real-world targets
🟢 OpenAI's Dots Keep What They Read Even After You Disconnect the App
OpenAI launched dots at DevDay on 29 September. They are "always-on agents", powered by GPT-6 Astra, each with its own cloud computer. Through plugins they "can readily connect to over 4,000 apps." They also work unprompted. OpenAI calls it "proactive research", using tools "restricted to be read-only", so a dot can't send messages in the background. What it reads, it keeps. "Disconnecting an app does not delete information your dot has already obtained from it." To clear that, you delete the dot. Dots come with Pro and Business Premium. Pro users in the UK, the EEA and Switzerland are left out at launch. Team mode is where it gets risky. One trust domain means one blast radius, and SpaceXAI's new Team Bots are team mode. "The plugins, secrets, skills, and files the owner adds are available in every teammate's conversation."
- OpenAI: Introducing dots
- OpenAI Help: Getting started with your dot
- SpaceXAI: Team Bots
- SpaceXAI docs: Team Bots
🟠 Citrix NetScaler Attacks Hit Dozens of Organisations, and Patching Won't Evict Them
Last week's two exploited NetScaler zero-days now have a damage report. Mandiant says the intrusions "impacted dozens of organizations". It expects "broad and opportunistic exploitation" by a variety of threat actors. Attackers drop a new PHP web shell called WHIPSHOT and a Python tunneller called SLAPSHOT. One payload creates a superuser account named sec_monitor. Another maps its web shell to URLs that look like NetScaler CSS files. Unit 42 traced the first fingerprinting to 21 August, weeks before disclosure. It counts 50,277 exposed instances that could be vulnerable. And it warns that patching "will not remove access" for attackers who are already in. So patch, then hunt. Look for accounts you didn't create, and web shells dressed up as stylesheets.
- Google Threat Intelligence: Defending against active exploitation of Citrix NetScaler
- Unit 42: NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 exploited in the wild
- LevelBlue SpiderLabs: CVE-2026-88771 exploitation artifacts and hunt indicators
- The Hacker News: NetScaler post-exploitation payload creates superuser
🟡 Google Gives Gemini 4 Argon to Defenders First, Without Cyber Guardrails
Google announced Gemini 4 Argon on 30 September, then gave it to almost nobody. It is "rolling out to a set of trusted cyber defenders" through the Fairwind Program, which has over 650 partners. Those defenders get it "without cyber guardrails". It sets a new high on DeepSWE v1.1 at 77.9%, and ties for first on CWE-bench v1 at 68%. The output limit jumps to 1M tokens, up from 64K. Launch pricing is $2 input and $10 output per million tokens. After the introductory period it becomes $4 and $20. Artificial Analysis is cooler. It scores Argon 53, level with GPT-6 Astra and five points under Opus 5.5. It also measured a 15% hallucination rate, against 51% for Astra. Google did the same with Gemini 3.8 Flash Cyber. My piece on the future of cybersecurity explains the rush. The average time from patch to exploit is now minus 7 days.
- Google: Gemini 4 Argon, our next era of frontier intelligence
- Google DeepMind: The Fairwind Program
- Artificial Analysis: Gemini 4 Argon
- Future of Cybersecurity (2026): 3 Things AI Just Broke — by Nathan House
⚫ FortiMail Has an Exploited 9.8 Zero-Day, and Cisco SD-WAN Joins CISA's List
Fortinet says CVE-2026-104286 in FortiMail "has been reported to be exploited in the wild." It scores 9.8. An unauthenticated attacker can write arbitrary files through crafted HTTP or HTTPS requests. Fixed releases are 8.0.2, 7.6.7 and 7.4.9. Users on 7.2 have to move to 7.4. If your fix isn't out yet, Fortinet's workaround is to disable IBE encryption and keep the management interface off the internet. Its indicators include an added /data/etc/ld.so.preload and a modified /bin/smit. CISA added the flaw to its exploited list on 1 October, with a federal deadline of 4 October. The day before, it added Cisco Catalyst SD-WAN Manager's CVE-2026-76504, also 9.8. Cisco says to look for usernames starting with "viptela-reserved-". The flaw gives an unauthenticated remote attacker admin privileges.
- Fortinet PSIRT: FG-IR-26-175
- CISA: Adds one known exploited vulnerability (FortiMail)
- CISA: Adds one known exploited vulnerability (Cisco)
- The Hacker News: Critical FortiMail zero-day exploited in attacks
- The Hacker News: CISA adds exploited Cisco Catalyst SD-WAN Manager auth bypass
🟪 Claude Sonnet 5.5 Costs Half of Opus per Token but More per Task
Anthropic released Sonnet 5.5 on 28 September. It costs $2 input and $10 output per million tokens. That's half of Opus 5.5, and the same as Sonnet 5. It tops Terminal-Bench 4.0 at 70.6%, and Opus 5.5 wins most of the rest. The benchmarks ran "at max effort", which is where the bill moves. Artificial Analysis scores Sonnet 5.5 at 56, two points behind Opus. It used about 193k output tokens per task, "the most we have measured". So a task cost $7.60, against $5.98 for Opus 5.5. The default effort in Claude Code is Medium. It's also the first Sonnet with cyber safeguards, and higher-risk security tasks "visibly fall back to Sonnet 5." On 1 October Claude Code got mods, TypeScript functions that change how it works. Treat one like any dependency you install. Mods "aren't sandboxed", and a mod can approve a permission request.
- Anthropic: Introducing Claude Sonnet 5.5
- Artificial Analysis: Claude Sonnet 5.5
- Artificial Analysis: Claude Opus 5.5 model page
- Claude: Customize Claude Code with mods
⚙️ OpenAI and AWS Both Shipped Decision Models in Jev's First Month
Jev has company. At DevDay, OpenAI announced a Decisions API. It focuses Luna "on a specific set of user-defined questions with finite pre-defined answers." It's in limited preview. Two days later, AWS's open-source Strands Labs released Strands Decider 2B. It takes Qwen3.5-2B and removes the LM head, "taking away its ability to generate text." It runs on a local CPU or GPU, with a median decision time of around 115ms. The licence is Apache 2.0. Like Jev, both return an answer from a fixed set instead of text. The same warning applies. Do not mistake an output format for a security boundary.
- OpenAI: DevDay 2026 recap
- Strands Agents: Introducing Strands Decider 2B
- GitHub: strands-labs/strands-decider
🟤 The FBI Says the Arrested Dutchman Is an Alleged ShinyHunters Leader
Last week Dutch police confirmed an arrest in a ShinyHunters investigation. On 29 September the FBI joined in. It and Dutch police said the 24-year-old from Amsterdam is a suspected member of the group. FBI Director Kash Patel called him "one of the alleged leaders". The FBI says the group allegedly breached more than 140 organisations and took at least $70 million in extortion payments. He was arrested on 15 September, days before the FBI hack claim surfaced. He also faces a separate case alleging attempted incitement to two murders. The FBI has told staff that some employees' personal data was stolen. Reuters had already verified more than 22 people in a 5,000-line sample. It lists staff working on China, Russia, telecom intercept and human intelligence.
- CBS News: Dutch police arrest member of group that claimed to have hacked FBI
- TechCrunch: Dutch police arrest ShinyHunters hacker accused of planning two murders
- Reuters (via WTVB): Hacked FBI data has sensitive information about employees' intelligence roles
🟩 OpenAI Added a $500 ChatGPT Plan and Priced GPT-6.1 Sol at a Fifth of Astra
GPT-6.1 Sol shipped at DevDay. It costs $2 input and $10 output per million tokens, against $10 and $50 for GPT-6 Astra. OpenAI says it "nearly matches" Astra on agentic coding, computer use and professional work. Artificial Analysis scores it 52 to Astra's 53, at $0.72 a task against $3.26. It's in ChatGPT Work and Codex, but "not yet available in Chat." The plans moved too. Pro now comes in $100, $200 and $500 tiers. New Pro 200 subscribers get a lower allowance than before. Pro 500 adds Astra Ultrafast, at up to 300 tokens per second in Codex. In the API, Ultrafast costs six times the standard rate: $60 and $300. In ChatGPT it uses your allowance eight times faster. I already spend $1,000 a month on AI subscriptions. I worked out whether running models locally beats that.
- OpenAI: Introducing GPT-6.1 Sol
- OpenAI Help: About ChatGPT Pro tiers
- OpenAI API: Pricing
- Artificial Analysis: GPT-6.1 Sol replaces GPT-6 Sol after just 7 days
- Self-Hosted AI: I Spend $1,000 a Month on Claude. Worth It? — by Nathan House
🕵️ Pentagon Breach Exposed Unencrypted Records on 2.76 Million People
The Pentagon is notifying current and former service members that their data was stolen. A defense official told ABC the breach affected 2.76 million living people and 294,000 who are deceased. Unauthorised users had access to a Defense Manpower Data Center system between October 2025 and July 2026. The notice says they exploited a flaw in an unspecified file-sharing system. The records weren't encrypted. They include Social Security numbers, dates of birth and details of military service. DMDC holds more than 60 million records. Nobody knows who did it yet. Officials say they've seen no evidence of misuse so far.
- ABC News: Pentagon breach exposed sensitive data on nearly 3 million people
- TechCrunch: Hackers stole millions of US military personnel records
🏛️ Trump Ordered Agencies to Say "Super Intelligence", and Six AI Chiefs Signed a Safety Pledge
Two things happened at the White House on 29 September. First, Executive Order 14434. The executive branch must now use "Super Intelligence" and "SI" in place of "Artificial Intelligence" and "AI". It binds federal agencies, not companies. Second, a voluntary accord. Pichai, Amodei, Zuckerberg, Brockman, Musk and Huang signed it, alongside Trump. Bezos and Nadella attended but didn't sign. It has four layers: internal controls, an internal team to check them, an independent external auditor, and a board committee. Layer one is the security one. Labs commit to ensure their models "do not hack or access technical systems in unintended ways." The accord says it "may make sense to codify these steps into laws or regulations" over time. Nothing enforces it yet.
- White House: Inaugurating the Era of Super Intelligence (EO 14434)
- White House Accord on Super Intelligence, signed text (via PBS NewsHour)
- PBS NewsHour: Trump announces accord signed by top AI companies to "self-police" development
🚔 Police Arrest KillSec's Alleged 16-Year-Old Leader
Police have dismantled KillSec, a ransomware-as-a-service crew run largely by teenagers. Its suspected leader is 16, and The Record reports he is Romanian. Officers raided eight houses in Greece, Romania, Britain and Spain, and seized five servers and the leak site. Europol links the group to some 1,000 attacks worldwide. The Record says at least half succeeded. One suspected developer turned 18 in August. Separately, a US grand jury in Puerto Rico indicted Dutch national Fouad Eltibrizi on 16 September. He allegedly goes by "Archduke" online.
- Europol: Teenager suspected of leading KillSec ransomware group
- The Record: Police disrupt KillSec ransomware, arrest suspected teenage leader
- US DOJ: Dutch national indicted and arrested for unauthorized computer access conspiracy
🎙️ ElevenLabs v4 Clones a Voice From 10 Seconds of Audio
ElevenLabs launched Eleven v4 on 28 September, its "most emotive text-to-speech model yet." It covers more than 90 languages. The Turbo variant has a median inference latency of about 100ms. The security line sits in the cloning section. "Instant Voice Clones can now capture voices with high fidelity using just 10 seconds of audio." Microsoft shipped MAI-Voice-2.1, in 23 languages at $22 per million characters. It also launched MAI-Transcribe-2-Streaming. Words can appear in the transcript as early as 320 milliseconds after they're spoken. I use ElevenLabs the other way round. Scribe v2 is my speech-to-text default, at a 2.2% error rate for $0.22 an hour. I scope its API key to speech-to-text only, so a leaked key can't touch text-to-speech. Put those pieces together and a live, cloned voice on a phone call gets cheaper. My social engineering stats page has the fraud numbers. Deepfake vishing rose 1,633% in a single quarter. The best defence is still dull: call back on a number you already know.