AI and IT News Recap: September 1, 2026: Anthropic's Fable 5.1 Redraws Venus and Cuts Costs 25%, a BGP Hijack Poisons a Software Update, and 22,000 Exchange Servers Sit Wide Open
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 1, 2026

Your fast, no-spin read on the AI and IT news that actually matters to a business owner today. Tuesday brought a frontier model launch with a real price cut attached, a routing hijack that poisoned a software update at the network layer, and a Microsoft outage that ran most of a business day.
📌 The AI and IT news at a glance
- 🔝 Anthropic shipped Claude Fable 5.1 and Mythos 5.1, cut typical costs about 25%, and showed the model redrawing a third of Venus from 30-year-old radar data.
- 🤖 OpenAI said ChatGPT Ads hit a billion annualized run rate in under 200 days and opened self-service buying across India, Europe, the Middle East, and North Africa.
- 🛡️ Softaculous disclosed that a BGP hijack diverted its update traffic and pushed a malicious Virtualizor update to hosting providers.
- 🛡️ JFrog Artifactory has a perfect-9.8 authentication bypass that attackers began exploiting to mint admin tokens four days after the patch shipped.
- 🛡️ Langflow instances are being looted for OpenAI API keys and AWS secrets, with observed attacks climbing to 360.
- 🛡️ Nearly 22,000 Exchange servers remain unpatched against a mailbox takeover flaw that already has public exploit code.
- 🛡️ Microsoft 365 broke for roughly a day, taking Exchange Online, Teams, SharePoint, Purview, and Defender XDR with it.
- 🛡️ Aesto Health disclosed a breach affecting 9.5 million patients, traced to an intrusion back in December 2025.
- 🧰 Google gave Gemini agentic video understanding, cutting video analysis token use by up to 88% at no extra feature cost.
- 🧰 OpenAI connected ChatGPT for Healthcare to Epic and nine official public healthcare data sources.
Missed yesterday? Catch up with the August 31 recap.
🔝 Top story: Anthropic ships Fable 5.1, drops the price, and points it at science
Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on Tuesday. They are the same underlying model with two different levels of safeguards. Fable 5.1 is generally available to everyone, while Mythos 5.1 is gated behind trusted access programs for vetted cybersecurity defenders and life sciences researchers. On benchmarks the jump is real rather than cosmetic. Terminal-Bench-Science went from 24.7% on Fable 5 to 52.6%. Terminal-Bench 4.0 agentic coding rose from 42.0% to 55.8%, and 60.9% for Mythos 5.1. AutomationBench, which measures business workflow completion, nearly doubled from 17.1% to 31.4%.
The part most owners will feel is the price. Anthropic cut cache read pricing by 75%, to $0.25 per million tokens, which works out to roughly 25% lower cost for typical workloads and up to about 45% for heavy agentic work where the model rereads a lot of context. Base pricing is unchanged at
0 per million input tokens and $50 per million output. Anthropic also announced Enterprise Frontier Safeguards, built with more than 100 customers, which keeps enterprise data in the customer's own cloud rather than Anthropic's and delivers zero-data-retention privacy while still allowing misuse detection. It rolls out in phases starting this fall, and eligible customers can run Fable 5.1 with zero data retention until then. Cybersecurity safeguards were loosened too, with Claude Code users expected to see roughly 60% fewer safeguard interruptions per session, and Fable 5.1 now permitted to find software vulnerabilities though not to write exploits for them. The science demos are the eyebrow-raiser. Claude trained a neural network that produced a new elevation map of a third of Venus from NASA Magellan radar data collected more than 30 years ago, sharpening resolution from 10 to 20 kilometers down to 2 to 3 kilometers.In short: Anthropic released Claude Fable 5.1 and Mythos 5.1 with large benchmark gains, roughly 25% lower typical cost, and a new enterprise data retention model.
What it means for your business: If you already pay for agentic AI work, your per-task bill likely just dropped without you doing anything, and the data retention objection that has stalled a lot of enterprise AI deals now has an answer worth raising with your vendor.
My take: The cache read discount is the quiet headline. Most real agentic work is the model rereading the same context over and over, so cutting that line item matters more to a monthly invoice than any benchmark on the page. I would also read the safeguards change carefully rather than cheer it. Fewer false positives is genuinely useful if your team does defensive security work and kept getting blocked, but "the model can now find vulnerabilities" is a capability that cuts both directions no matter whose logo is on it.
Source: Introducing Claude Fable 5.1 and Claude Mythos 5.1, Anthropic
🤖 AI
ChatGPT Ads crosses
billion annualized in under 200 daysOpenAI said on Monday that ChatGPT Ads reached a
billion annualized revenue run rate less than 200 days after launch, with tens of thousands of advertisers now on the platform. Self-service buying through Ads Manager opened across India, Europe, the Middle East, and North Africa, adding to availability in more than 40 countries. OpenAI frames advertising as one pillar alongside subscriptions, enterprise, and API usage, and says the ad-supported free tier is what keeps ChatGPT reachable for more than a billion weekly users.The company was specific about guardrails. Ads are labeled and separated from ChatGPT's answers, advertising does not influence what ChatGPT says, and advertisers do not get access to private conversations. The system uses conversation context to pick a relevant ad, and depending on country and user settings, may also draw on broader ChatGPT history. On results, OpenAI cited an ecommerce advertiser hitting 3x return on ad spend over 28 days and a technology partner reporting that more than 80% of ad-driven ChatGPT traffic came from new customers.
In short: OpenAI's advertising business hit a
billion annualized run rate and opened self-service ad buying across India, Europe, the Middle East, and North Africa.What it means for your business: A new high-intent channel just opened to small and mid-sized advertisers, and separately, your own brand may now be appearing next to ads inside the tool your customers use to compare vendors.
My take: Worth watching from two seats at once. As a buyer, this is early-channel pricing on people who are actively deciding, which historically does not last. As a business being researched, the more interesting question is not whether to advertise but whether ChatGPT describes your company accurately when someone asks, because that answer is the part ads explicitly do not influence.
Source: A milestone in expanding access to AI, OpenAI
🛡️ IT and security
Hackers hijacked internet routing to poison a software update
Softaculous disclosed that between 20:57 UTC on August 28 and 06:10 UTC on August 30, an attacker announced a false BGP route for a block of Hetzner-hosted IP addresses, diverting traffic bound for the company's software update systems and its client and billing portal. Any Virtualizor installation that checked for updates during that window could have been served a malicious package instead of a real one. Virtualizor is a VPS control panel that hosting providers use to create and manage virtual servers, so a compromised install sits underneath other people's infrastructure.
Softaculous says only a handful of servers actually received the malicious update, but it cannot be certain, because the requests were redirected away from its own systems and it therefore has no logs of them. Admins should check for a service file at /etc/systemd/system/java-jre-update.service, and if it exists, rotate and restrict API credentials and audit for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Anyone who logged into the Softaculous client area or entered payment details during the window should reset passwords and watch card statements. Routing has been restored, a fraudulent certificate was reported for revocation, and Virtualizor 3.2.9.9 shipped September 1 with a new Security Analyzer tool. Softaculous also says it will start cryptographically signing all packages going forward.
In short: Attackers hijacked BGP routing for Softaculous update servers and delivered a malicious Virtualizor update to a small number of hosting providers.
What it means for your business: Automatic updates are still the right default, but this is a reminder that "the update came from the vendor" is an assumption your systems make on your behalf, and that assumption can be forged at the network layer.
My take: The line that stuck with me is that the vendor has no logs, because the traffic never reached them. That is the uncomfortable part of a routing attack: the victim and the vendor both end up reconstructing events from an absence. The fix here is not exotic. Signed packages would have made this a non-event, and it is fair to ask any vendor shipping software into your environment whether they sign their releases and whether your systems actually verify the signature.
Source: Hackers push malicious Virtualizor update in BGP hijacking attack, BleepingComputer
A critical JFrog Artifactory flaw went from patch to exploitation in days
Attackers began weaponizing CVE-2026-82329 on September 1, according to watchTowr. The flaw is an authentication bypass in JFrog Access carrying a CVSS score of 9.8, and it affects default configurations with no authentication and no user interaction required. Instances without an additional join key configured receive what watchTowr calls a "phantom" join key, which an attacker can abuse to forge access and mint administrator-level credentials. JFrog patched it in Artifactory 7.161.20, released August 28, with fixes across the 7.111, 7.117, 7.125, 7.133, 7.146, and 7.161 branches.
The reason this matters more than a typical 9.8 is what Artifactory is. It is the binary repository sitting in the middle of a software supply chain, holding the packages and images that get deployed everywhere else. watchTowr's Yordan Ganchev says attackers are already generating admin tokens and enumerating users, groups, credential sets, and federated access topologies. Vercel CEO Guillermo Rauch called it an "RCE bomb" on the grounds that admin access to Artifactory means you can poison everything downstream of it.
In short: A CVSS 9.8 authentication bypass in JFrog Artifactory is being actively exploited to mint admin tokens, four days after the patch shipped.
What it means for your business: If your development team self-hosts Artifactory, this is a same-day patch, and patching alone is not enough, because tokens minted before you patched keep working.
My take: Four days from patch to in-the-wild exploitation is the pattern now, not the exception, and it quietly changes what a reasonable patch window looks like for internet-facing developer infrastructure. Note also that this is a default-configuration problem. Nobody misconfigured anything. That is the kind of bug that catches careful teams alongside careless ones.
Attackers are looting OpenAI and AWS keys through Langflow
VulnCheck reported that threat actors are exploiting CVE-2026-0768, an unauthenticated remote code execution flaw in Langflow's custom component editor, to harvest credentials from exposed instances. Langflow is a popular open-source, Python-based low-code platform for building AI apps, agents, chatbots, and RAG systems, which means the boxes running it tend to hold exactly the secrets an attacker wants sitting in environment variables. VulnCheck lead researcher Caitlin Condon said attacker requests are querying LANGFLOW_SUPERUSER, OPENAI_API, AWS_ACCESS, and AWS_SECRET variables, reading the Langflow secret key file, and checking SSH access and bash history.
Volume climbed fast. VulnCheck's UK honeypots logged at least 50 exploitation attempts over the weekend, with traffic originating primarily from Russia, rising to 360 observed attacks by Tuesday. There are no known public proof-of-concept exploits, which suggests a reasonably capable actor rather than opportunistic scanning. The flaw was disclosed back in January and affects Langflow 1.4.2 and earlier. Worth being clear that this is a different bug from the Langflow issue CISA flagged earlier this year, CVE-2026-9198. Version 1.11.6 addresses all known flaws.
In short: Attackers are exploiting an unauthenticated RCE in Langflow to steal OpenAI API keys, AWS secrets, and superuser credentials, with observed attacks rising to 360.
What it means for your business: Cloud and AI API keys are money, and a stolen OpenAI key can run up a bill quickly, so any AI prototyping server somebody spun up months ago deserves an inventory check today.
My take: This is the shadow IT problem wearing a 2026 outfit. Low-code AI builders get stood up by an enthusiastic team member, they collect production credentials because that is what makes the demo work, and then nobody owns patching them. Ask who runs your AI tooling servers, and if the answer takes more than a minute to produce, that is the finding.
Source: Critical Langflow flaw exploited to steal OpenAI and AWS keys, BleepingComputer
Nearly 22,000 Exchange servers still open to full mailbox takeover
Shadowserver counted 21,899 internet-exposed Microsoft Exchange servers still unpatched against CVE-2026-62911 as of Tuesday, most of them in the United States at around 6,200 and Germany at around 5,100. The flaw is an authentication bypass by capture-replay reported by DEVCORE's Orange Tsai, affecting Exchange Server 2016, 2019, and Subscription Edition. Microsoft's own description is blunt about the impact: an attacker "would be able to take over the mailboxes of all Exchange users," including sending mail, reading mail, and downloading attachments. Microsoft patched it in the August 2026 Patch Tuesday.
It has not been confirmed as exploited in the wild yet, but the Netherlands National Cyber Security Centre reported last week that exploit code is already available online, and Germany's BSI warned on Friday that roughly 85% of all on-premises Exchange servers in Germany remain vulnerable. There is a deadline attached, too. Exchange 2016 and 2019 only receive updates through the Extended Security Updates program, and those updates stop shipping in October 2026.
In short: Nearly 22,000 exposed Exchange servers remain unpatched against a mailbox takeover flaw that already has public exploit code.
What it means for your business: If you still run Exchange on-premises, patch this week, and start the migration conversation now, because extended security updates for Exchange 2016 and 2019 end next month.
My take: The October cutoff is the real story buried under the number. Patching this specific bug is a Tuesday afternoon. Running an internet-facing mail server that stops receiving security updates in five weeks is a strategic problem, and it does not get cheaper by waiting. If nothing else, use this as the forcing function to get a decision on the calendar.
Source: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks, BleepingComputer
Microsoft 365 spent most of a day broken
Microsoft acknowledged a service incident at 5:30 PM UTC on August 31 after a wave of user reports about Exchange Online, and it grew from there. The company confirmed the outage also hit OneDrive for Business, SharePoint Online, Teams, Purview, and Defender XDR. Symptoms included delayed and failed email, broken mailbox search, authentication errors, and failures in admin consoles. Downdetector showed tens of thousands of affected Outlook and Microsoft 365 users.
Microsoft traced it to "issues related to a core authentication configuration used by multiple internal services within the Exchange Online infrastructure," and had to run manual server-level configuration resets to fix it. Recovery was slow. Roughly 22 hours after the incident was acknowledged, Microsoft was still reporting positive recovery trends rather than resolution, and mail flow and search were not confirmed restored until midday Tuesday. This is the latest in a run of Exchange Online outages, following incidents in April and June.
In short: A core authentication configuration problem took down Exchange Online and several other Microsoft 365 services for roughly a day.
What it means for your business: Your continuity plan probably assumes email works, and for most of a business day it did not, which is worth a conversation about a backup channel your team can actually reach when Microsoft authentication is the thing that is broken.
My take: What makes this one instructive is the blast radius. It was not really an email outage, it was an authentication outage, and authentication sits underneath everything. Defender XDR going down alongside the services it is supposed to watch is the detail I would flag to any leadership team. When your monitoring and your monitored systems share a dependency, you lose both at once. A cheap out-of-band chat channel and a printed contact list are unglamorous, and they are what people actually reach for.
Source: Massive Microsoft 365 outage causes auth issues, service failures, BleepingComputer
Aesto Health breach reaches 9.5 million patients
Aesto LLC, operating as Aesto Health, told the U.S. Department of Health and Human Services that a data breach affects 9,540,683 individuals. The company sells software that helps healthcare organizations migrate, archive, and access patient data when they replace EHR systems or acquire practices, which is why a single vendor compromise reaches so many people. HIPAA Journal reports the incident indirectly affects 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health.
The timeline is the uncomfortable part. The intrusion happened between roughly December 2 and December 18, 2025. Aesto confirmed it internally on May 26, 2026 after a forensic investigation, posted a public notice on June 24, and only began notifying affected individuals on August 21. The exposed data includes full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government IDs, and Social Security numbers. Affected people are being offered 24 months of Experian identity protection. No threat group has publicly claimed the attack.
In short: Healthcare data vendor Aesto Health disclosed that a December 2025 intrusion exposed records belonging to more than 9.5 million patients across 29 providers.
What it means for your business: Your vendors' breaches become your breaches in the eyes of your customers, so it is worth knowing which of your suppliers holds regulated data and how quickly their contract obligates them to tell you.
My take: Eight months from intrusion to individual notification is the number to sit with. Some of that is genuinely slow forensic work on unstructured documents, and some of it is just how long these things take. Either way, if a supplier of yours is breached in December, you may not hear about it until the following August. That argues for building your vendor risk picture from what data they hold rather than from their incident history, because the history arrives late.
Source: Aesto Health says data breach affects over 9.5 million patients, BleepingComputer
🧰 New tooling for builders and business
Gemini learns to watch video the way a person would
Google launched agentic video understanding on September 1 across Gemini 3.7 Flash, 3.6 Flash, and 3.5 Flash-Lite. Instead of ingesting a video at a fixed frame rate, which is how most video analysis works today, the model actively decides what to watch, at what speed, and through which channel, whether frames, audio, or transcript, and fetches only the segments it needs. Google reports up to 88% lower token consumption, up to 66% lower cost, and up to 7% better accuracy on standard video benchmarks, with the biggest gains on long content where fixed-rate processing forces you to choose between huge bills and dropped detail.
It is live now through the Gemini API in Google AI Studio and the Gemini Enterprise Agent Platform, for both uploads and YouTube videos, and it is enabled by setting processing to "agentic" in the API config. There is no extra feature fee, just standard token pricing. Google says the capability will roll out to Gemini app users soon and will eventually power YouTube's "Ask YouTube" feature on the watch page.
In short: Google shipped agentic video understanding for Gemini Flash models, cutting video analysis token use by up to 88% at no additional feature cost.
What it means for your business: Analyzing recorded calls, training footage, security video, or a webinar library just got roughly a third cheaper, which moves a lot of "someday" video projects into budget.
My take: The practical unlock is long-form. Anything over about 20 minutes was previously expensive enough that most teams either sampled it badly or skipped it. Finding a specific moment across hours of recordings is now a reasonable thing to ask for. If you have a video archive nobody has ever searched, this is a good quarter to try.
Source: Introducing agentic video understanding with Gemini, Google
ChatGPT plugs into Epic and nine official healthcare data sources
OpenAI announced on September 1 that healthcare organizations can connect Epic environments to ChatGPT for Healthcare, letting clinicians ask what changed since a patient's last visit or which labs to review before an appointment, with answers pointing back to supporting chart information. It works two ways: pulling authorized patient context into ChatGPT, or embedding ChatGPT into the EHR layout so clinicians do not leave the chart. UCSF Health is a pilot partner.
Alongside it, a new Healthcare Public Data plugin gives structured access to nine official sources including ClinicalTrials.gov, CMS Coverage, RxNorm, DailyMed, and PubMed, so teams can compare trial eligibility criteria or confirm a medication's latest label without visiting each site separately. On validation, OpenAI says physicians reviewed responses across 27 clinical use cases and rated 99.1% of 4,363 responses as safe, and that more than 93% of responses were rated "good" or better for accuracy across each of the five connected data sources tested. HIPAA workflows require an applicable Business Associate Agreement, and the EHR integration is not available to individual accounts.
In short: OpenAI launched an Epic EHR integration and a nine-source public healthcare data plugin for ChatGPT for Healthcare.
What it means for your business: If you run a clinical practice, the governance questions just got concrete, because the tool now touches the patient record and a BAA plus workspace admin approval are the gate.
My take: The safety numbers are the right things to publish, and they still deserve a careful read. A 99.1% safety rate across 4,363 ratings means roughly 39 responses were not rated safe, which is fine for a tool clinicians review and not fine for one they trust unread. The framing OpenAI uses, preparing work that clinicians review, is the correct one. Whether it survives contact with a busy clinic schedule is the thing to watch.
Source: Healthcare organizations can now connect EHR and additional industry data to ChatGPT, OpenAI
That is the AI and IT news that matters for September 1, 2026. Have a question about how any of this hits your business? Reach out to the KeyChange team, and check back tomorrow for the next recap.