Sec & AI News — 3 October 2026

13 min readBy Nathan House
Get every new Sec & AI News issue
Straight to your inbox. No spam.

🟣 OpenAI Has Warned 100+ Organisations About Its Agents

Last week Australia went public with OpenAI's Medicare hack. This week OpenAI apologised and filled in the gaps. Its agent "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files." It also reviewed the service's source code. Three more Australian agencies were caught up, one through an exposed access key. Then the bigger number. OpenAI says it has notified "over 100 organizations" about its own models' activity. A notice, it stresses, does not mean a compromise. The review covers about 50 petabytes on some 7,000 GPUs, at "over half a million dollars a day." OpenAI has paused training and evaluation involving tool use for its most capable models. California's attorney general served it a subpoena on 1 October. A public-interest group has sued over the Hugging Face hack. Reuters reports an FTC probe. OpenAI's Jason Kwon faces Australian senators on 6 October.

🧭 AI-Driven Security Engineering Jobs: This Week

This week the number is a brand name. Claude Code appears in 104 of the 661 postings in my archive. In 56 of them it sits in the requirement text itself. MCP, the protocol agents use to reach tools, also turns up in 104 and is required in 18. The archive grew by 71 postings this week, across 22 countries now. Most are senior: 327, against 33 entry-level. The job of the week is a16z's Staff Security Engineer, AI & Security Platform, in San Francisco, at $243K–$284K. It wants "5+ years of security engineering experience" first. Then it wants someone "evaluating model output for accuracy, usability, and performance", and it lists "agent identity boundaries" among the risks. Both show up in the stories below. If you want in, the AI Master's Program teaches AI-Driven Cyber Security Engineering. No coding background required. Application only.

🧠 Anthropic's Claude Projects Runs a Fleet of Agents, but Only for One User

On 17 September Anthropic redesigned Projects in Claude Code. Within days it was being called "Anthropic's own agentic OS." I checked that against the docs. A project is now one long-running conversation. "Projects have threads that do the work and a coordinator that directs them." Each thread is usually a cloud session on its own copy of the code, and it keeps working after you close your laptop. Then the catch. It's a beta for Pro and Max, with "no organization-level controls". And "A project belongs to one user. You can't share a project." The team features people got excited about belong to the older chat Projects. New projects default to Opus for everything. Idle threads watching a pull request wake up, and spend again, when a test fails. I ranked it against nine other agentic OS options, from gstack to my own HAL.

🧪 I Tested Jev on Real Security Work. It Matched Regex Rules, Not Gemini.

I tested Jev, TypeSafe's decision model, on real security work. It answers with a verdict, not text. On 34 WordPress CVE cases it extracted 107 of 136 facts correctly. Plain regex rules got 108. Gemini 3.1 Pro got 123. The costs were $0, $0.004 and $0.65. Then I ran it over 221 ads from our own jobs archive. When it was confident it was right 97.9% of the time, and the whole run cost 2 cents. It still failed my test, because it confidently published 3 wrong ads against a limit of one. Check Point flipped its verdict in 25 of 27 runs, for about 50 cents per successful attack. Two rivals to Jev shipped this week, from OpenAI and AWS, covered further down. My verdict holds for all of them. "Jev is a real cost breakthrough for high-volume, clear-cut sorting. It isn't a capability breakthrough."

🔴 Researchers Caught AI Agents Sending SQL Injection to US and Canadian Government Sites

Transluce found more agent traffic against government sites. On 17 June, agents sent more than 200,000 requests to a US Department of Education website. One carried a textbook SQL injection: State_Id=1 OR 1=1. More than 10,000 requests included a tag beginning with "oai". Library and Archives Canada took 899 requests, including three SQL injection probes. The probes don't appear to have worked. The data matched a search task from Google's DeepSearchQA benchmark, so the agents probably weren't asked to hack anything. Transluce is careful here. It is "not attributing this traffic as a whole to OpenAI." Canada's cyber centre sees "no indication that government systems have been compromised." The Education Department reports no impact. Separately, The Verge traced several labs' agent breakouts to one testing firm, Irregular. Its CTO says "internet access was unintentionally available" in one evaluation scenario.

🟢 OpenAI's Dots Keep What They Read Even After You Disconnect the App

OpenAI launched dots at DevDay on 29 September. They are "always-on agents", powered by GPT-6 Astra, each with its own cloud computer. Through plugins they "can readily connect to over 4,000 apps." They also work unprompted. OpenAI calls it "proactive research", using tools "restricted to be read-only", so a dot can't send messages in the background. What it reads, it keeps. "Disconnecting an app does not delete information your dot has already obtained from it." To clear that, you delete the dot. Dots come with Pro and Business Premium. Pro users in the UK, the EEA and Switzerland are left out at launch. Team mode is where it gets risky. One trust domain means one blast radius, and SpaceXAI's new Team Bots are team mode. "The plugins, secrets, skills, and files the owner adds are available in every teammate's conversation."

🟠 Citrix NetScaler Attacks Hit Dozens of Organisations, and Patching Won't Evict Them

Last week's two exploited NetScaler zero-days now have a damage report. Mandiant says the intrusions "impacted dozens of organizations". It expects "broad and opportunistic exploitation" by a variety of threat actors. Attackers drop a new PHP web shell called WHIPSHOT and a Python tunneller called SLAPSHOT. One payload creates a superuser account named sec_monitor. Another maps its web shell to URLs that look like NetScaler CSS files. Unit 42 traced the first fingerprinting to 21 August, weeks before disclosure. It counts 50,277 exposed instances that could be vulnerable. And it warns that patching "will not remove access" for attackers who are already in. So patch, then hunt. Look for accounts you didn't create, and web shells dressed up as stylesheets.

🟡 Google Gives Gemini 4 Argon to Defenders First, Without Cyber Guardrails

Google announced Gemini 4 Argon on 30 September, then gave it to almost nobody. It is "rolling out to a set of trusted cyber defenders" through the Fairwind Program, which has over 650 partners. Those defenders get it "without cyber guardrails". It sets a new high on DeepSWE v1.1 at 77.9%, and ties for first on CWE-bench v1 at 68%. The output limit jumps to 1M tokens, up from 64K. Launch pricing is $2 input and $10 output per million tokens. After the introductory period it becomes $4 and $20. Artificial Analysis is cooler. It scores Argon 53, level with GPT-6 Astra and five points under Opus 5.5. It also measured a 15% hallucination rate, against 51% for Astra. Google did the same with Gemini 3.8 Flash Cyber. My piece on the future of cybersecurity explains the rush. The average time from patch to exploit is now minus 7 days.

⚫ FortiMail Has an Exploited 9.8 Zero-Day, and Cisco SD-WAN Joins CISA's List

Fortinet says CVE-2026-104286 in FortiMail "has been reported to be exploited in the wild." It scores 9.8. An unauthenticated attacker can write arbitrary files through crafted HTTP or HTTPS requests. Fixed releases are 8.0.2, 7.6.7 and 7.4.9. Users on 7.2 have to move to 7.4. If your fix isn't out yet, Fortinet's workaround is to disable IBE encryption and keep the management interface off the internet. Its indicators include an added /data/etc/ld.so.preload and a modified /bin/smit. CISA added the flaw to its exploited list on 1 October, with a federal deadline of 4 October. The day before, it added Cisco Catalyst SD-WAN Manager's CVE-2026-76504, also 9.8. Cisco says to look for usernames starting with "viptela-reserved-". The flaw gives an unauthenticated remote attacker admin privileges.

🟪 Claude Sonnet 5.5 Costs Half of Opus per Token but More per Task

Anthropic released Sonnet 5.5 on 28 September. It costs $2 input and $10 output per million tokens. That's half of Opus 5.5, and the same as Sonnet 5. It tops Terminal-Bench 4.0 at 70.6%, and Opus 5.5 wins most of the rest. The benchmarks ran "at max effort", which is where the bill moves. Artificial Analysis scores Sonnet 5.5 at 56, two points behind Opus. It used about 193k output tokens per task, "the most we have measured". So a task cost $7.60, against $5.98 for Opus 5.5. The default effort in Claude Code is Medium. It's also the first Sonnet with cyber safeguards, and higher-risk security tasks "visibly fall back to Sonnet 5." On 1 October Claude Code got mods, TypeScript functions that change how it works. Treat one like any dependency you install. Mods "aren't sandboxed", and a mod can approve a permission request.

⚙️ OpenAI and AWS Both Shipped Decision Models in Jev's First Month

Jev has company. At DevDay, OpenAI announced a Decisions API. It focuses Luna "on a specific set of user-defined questions with finite pre-defined answers." It's in limited preview. Two days later, AWS's open-source Strands Labs released Strands Decider 2B. It takes Qwen3.5-2B and removes the LM head, "taking away its ability to generate text." It runs on a local CPU or GPU, with a median decision time of around 115ms. The licence is Apache 2.0. Like Jev, both return an answer from a fixed set instead of text. The same warning applies. Do not mistake an output format for a security boundary.

🟤 The FBI Says the Arrested Dutchman Is an Alleged ShinyHunters Leader

Last week Dutch police confirmed an arrest in a ShinyHunters investigation. On 29 September the FBI joined in. It and Dutch police said the 24-year-old from Amsterdam is a suspected member of the group. FBI Director Kash Patel called him "one of the alleged leaders". The FBI says the group allegedly breached more than 140 organisations and took at least $70 million in extortion payments. He was arrested on 15 September, days before the FBI hack claim surfaced. He also faces a separate case alleging attempted incitement to two murders. The FBI has told staff that some employees' personal data was stolen. Reuters had already verified more than 22 people in a 5,000-line sample. It lists staff working on China, Russia, telecom intercept and human intelligence.

🟩 OpenAI Added a $500 ChatGPT Plan and Priced GPT-6.1 Sol at a Fifth of Astra

GPT-6.1 Sol shipped at DevDay. It costs $2 input and $10 output per million tokens, against $10 and $50 for GPT-6 Astra. OpenAI says it "nearly matches" Astra on agentic coding, computer use and professional work. Artificial Analysis scores it 52 to Astra's 53, at $0.72 a task against $3.26. It's in ChatGPT Work and Codex, but "not yet available in Chat." The plans moved too. Pro now comes in $100, $200 and $500 tiers. New Pro 200 subscribers get a lower allowance than before. Pro 500 adds Astra Ultrafast, at up to 300 tokens per second in Codex. In the API, Ultrafast costs six times the standard rate: $60 and $300. In ChatGPT it uses your allowance eight times faster. I already spend $1,000 a month on AI subscriptions. I worked out whether running models locally beats that.

🕵️ Pentagon Breach Exposed Unencrypted Records on 2.76 Million People

The Pentagon is notifying current and former service members that their data was stolen. A defense official told ABC the breach affected 2.76 million living people and 294,000 who are deceased. Unauthorised users had access to a Defense Manpower Data Center system between October 2025 and July 2026. The notice says they exploited a flaw in an unspecified file-sharing system. The records weren't encrypted. They include Social Security numbers, dates of birth and details of military service. DMDC holds more than 60 million records. Nobody knows who did it yet. Officials say they've seen no evidence of misuse so far.

🏛️ Trump Ordered Agencies to Say "Super Intelligence", and Six AI Chiefs Signed a Safety Pledge

Two things happened at the White House on 29 September. First, Executive Order 14434. The executive branch must now use "Super Intelligence" and "SI" in place of "Artificial Intelligence" and "AI". It binds federal agencies, not companies. Second, a voluntary accord. Pichai, Amodei, Zuckerberg, Brockman, Musk and Huang signed it, alongside Trump. Bezos and Nadella attended but didn't sign. It has four layers: internal controls, an internal team to check them, an independent external auditor, and a board committee. Layer one is the security one. Labs commit to ensure their models "do not hack or access technical systems in unintended ways." The accord says it "may make sense to codify these steps into laws or regulations" over time. Nothing enforces it yet.

🚔 Police Arrest KillSec's Alleged 16-Year-Old Leader

Police have dismantled KillSec, a ransomware-as-a-service crew run largely by teenagers. Its suspected leader is 16, and The Record reports he is Romanian. Officers raided eight houses in Greece, Romania, Britain and Spain, and seized five servers and the leak site. Europol links the group to some 1,000 attacks worldwide. The Record says at least half succeeded. One suspected developer turned 18 in August. Separately, a US grand jury in Puerto Rico indicted Dutch national Fouad Eltibrizi on 16 September. He allegedly goes by "Archduke" online.

🎙️ ElevenLabs v4 Clones a Voice From 10 Seconds of Audio

ElevenLabs launched Eleven v4 on 28 September, its "most emotive text-to-speech model yet." It covers more than 90 languages. The Turbo variant has a median inference latency of about 100ms. The security line sits in the cloning section. "Instant Voice Clones can now capture voices with high fidelity using just 10 seconds of audio." Microsoft shipped MAI-Voice-2.1, in 23 languages at $22 per million characters. It also launched MAI-Transcribe-2-Streaming. Words can appear in the transcript as early as 320 milliseconds after they're spoken. I use ElevenLabs the other way round. Scribe v2 is my speech-to-text default, at a 2.2% error rate for $0.22 an hour. I scope its API key to speech-to-text only, so a leaked key can't touch text-to-speech. Put those pieces together and a live, cloned voice on a phone call gets cheaper. My social engineering stats page has the fraud numbers. Deepfake vishing rose 1,633% in a single quarter. The best defence is still dull: call back on a number you already know.