AI and IT News Recap: September 4, 2026: OpenAI Ships Its First 'Critical' Cyber Model to Business Testers, Chrome Patches a Zero-Day Under Attack, and a Hijacked Registry Steals Developer Keys
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 4, 2026
Your fast, no-spin read on the AI and IT news that actually matters to a business owner today. Thursday was the day OpenAI shipped the model it had already labeled dangerous, both major AI assistants fell over within ninety minutes of each other, and a developer platform's own registry was quietly rerouted to hand out credential stealers.
📌 The AI and IT news at a glance
- 🔝 OpenAI began rolling out GPT-6 Astra, the first model it has ever rated "Critical" for cyber capability, to business testers in its Daybreak program.
- 🤖 Claude and ChatGPT both went down Thursday morning, roughly ninety minutes apart, with Anthropic's outage hitting seven model versions.
- 🤖 A top Pentagon official reaffirmed Anthropic's supply chain risk designation one day after the Commerce Secretary said the dispute was settled.
- 🛡️ Google patched a Chrome zero-day, CVE-2026-85046, that is already being exploited in attacks.
- 🛡️ Attackers hijacked Coder's registry infrastructure and served Terraform modules that stole cloud keys, CI/CD credentials, and SSH keys.
- 🛡️ A critical Elementor Pro flaw is under active attack, with Wordfence blocking nearly 200,000 exploitation attempts.
- 🛡️ A phishing campaign that installs legitimate remote management software has spread to 46 countries, with the US now its top target.
- 🛡️ France's privacy regulator fined a private hospital 500,000 euros over a breach exposing data on more than 727,000 people.
- 🧰 GitHub reopened Copilot Business and Enterprise signups and is moving card and PayPal customers to upfront per-seat billing on October 1.
- 🧰 GitHub will retire four models from Copilot on October 2, including Claude Opus 4.7 and two Gemini Flash versions.
Missed yesterday? Catch up with the September 3 recap.
🔝 Top story: OpenAI shipped the model it called critically capable at cyberattacks
OpenAI began rolling out GPT-6 Astra on Thursday to business customers in its Daybreak program, the invite-only track that gives approved testers access to its most capable models. The company also said a version carrying additional cybersecurity guardrails is headed to paying customers, with planned availability across ChatGPT Plus, Pro, Business and Enterprise, the OpenAI API, and Amazon Web Services. OpenAI framed the release as a milestone in its decade-long push toward artificial general intelligence, and said the model puts it back ahead of Anthropic.
The reason this launch is unusual is the label attached to it. Astra is the first model OpenAI has designated "Critical" under its Preparedness Framework, reflecting its own finding that the model can autonomously discover previously unknown security weaknesses and build working exploits against well-defended systems without a human directing every step. The company paused some internal work on Astra in August specifically to add stricter safeguards, and says the shipped versions refuse dangerous requests far more often than their predecessor: 91.5% refusal in cyber jailbreak evaluations, against 59% for GPT-5.6 Sol. OpenAI is also running chain-of-thought monitoring that can detect and interrupt actions falling outside authorized boundaries.
In short: OpenAI began rolling out GPT-6 Astra to business testers in its Daybreak program, the first model it has rated "Critical" for cyber capability, with a more heavily guardrailed version planned for paying ChatGPT customers.
What it means for your business: Nothing lands on your desk today, but the schedule matters. The capability OpenAI restricted to vetted testers is on a path toward general availability, which means the tooling that finds flaws in software is about to get much better on both sides of the fence, in months rather than years.
My take: The sequencing is what I keep coming back to. OpenAI decided this model crossed its own danger line, paused work in August to add guardrails, and shipped it a few weeks later. Both things can be true at once: the safeguards look like real engineering, and a 91.5% refusal rate still means roughly one attempt in twelve got through in the company's own testing. The number I would actually want is the refusal rate after six months of strangers probing it, and nobody publishes that. For a business owner the practical read is simpler than the debate. Assume whoever is scanning your systems is about to get better at finding unpatched holes, and spend the budget on shortening the gap between a patch shipping and you installing it, because that gap is where all of this eventually lands.
Source: OpenAI announces rollout of GPT-6 Astra model, CNBC
🤖 AI
Claude and ChatGPT both fell over the same morning
Thursday was a rough one for anyone whose workday runs through an AI assistant. Anthropic confirmed at around 9:41 AM Eastern that Claude was returning elevated errors, and the incident grew to cover a broad list of models: Mythos and Fable 5.1, Mythos and Fable 5, Opus 5, Opus 4.8, and Opus 4.6. Roughly ninety minutes later OpenAI confirmed an outage of its own, with ChatGPT and Codex users hitting errors across nearly every major feature, landing just ahead of the Astra rollout.
There is no evidence the two incidents were connected, and neither company tied either one to an attack. What made the morning notable was the overlap. For a few hours the two assistants that a great many businesses now route drafting, summarizing, coding, and customer response work through were both unavailable at the same time, which is a scenario most teams have never actually planned for.
In short: Claude and ChatGPT both suffered outages on Thursday morning within about ninety minutes of each other, with Anthropic's incident affecting seven model versions.
What it means for your business: If a workflow at your company stops when one AI vendor has a bad morning, that is a single point of failure worth naming out loud, and the fix is usually a documented manual fallback rather than a second AI subscription.
My take: Vendor outages are normal and neither of these was catastrophic. The useful part is what the morning exposed. Plenty of businesses have quietly moved real operational work onto these tools over the past year without ever writing down what happens when they are down, because the tools were a novelty when the process was designed and are load-bearing now. That is worth an hour of somebody's time this month. Which tasks stop? Who notices first? Is there a version of the job that still gets done by a person? If the honest answer is that your team just waits, that is fine for a two-hour blip and a genuine problem for a two-day one.
Source: Anthropic confirms Claude is down, multiple models affected, BleepingComputer
The Pentagon and the Commerce Department told opposite stories about Anthropic
Emil Michael, the under secretary of defense for research and engineering, posted on X on Thursday that "Anthropic is still a designated Supply Chain Risk" at the Defense Department and for the defense industrial base. The message arrived one day after Commerce Secretary Howard Lutnick told Bloomberg Television that Anthropic had "gotten religion" and patched up its differences with the administration, and told Axios that the administration trusts the company.
The underlying dispute traces back to a 00 million contract disagreement over how the Pentagon could deploy Claude on classified systems. Anthropic sought contractual limits barring use of its models in autonomous lethal weapons systems or domestic mass surveillance, and the Defense Department rejected the premise that a contractor gets to set military operating rules. A federal judge in San Francisco ruled for Anthropic last week and told the government to lift its ban, while a separate appeal is underway in Washington.
In short: A senior Pentagon official publicly reaffirmed Anthropic's supply chain risk designation on Thursday, contradicting the Commerce Secretary's statement a day earlier that the dispute had been resolved.
What it means for your business: If you sell to federal agencies or sit anywhere in the defense supply chain, do not treat press statements about a vendor's standing as a change to your own compliance position until the designation itself actually moves.
My take: Two cabinet-level parts of the same government said opposite things about the same vendor twenty-four hours apart, and that is worth noting regardless of where you land on the underlying argument. The substantive question is a real one that reasonable people disagree on: whether a supplier can attach conditions to how its product gets used by a customer whose job is national defense. But the lesson for anyone buying software is procedural rather than political. A vendor's status with a government customer is a legal designation, not a mood, and the only version that counts is the one written down. If your contracts reference a vendor's standing, watch the filings, not the interviews.
Source: Top Pentagon official reaffirms Anthropic blacklist despite Lutnick comments, Axios
🛡️ IT and security
A Chrome zero-day is already being used in attacks
Google shipped a Chrome update on Friday fixing CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine that is already being exploited in the wild. The same update closes eleven other vulnerabilities, nine of them high severity, spanning Crash Reporting, Network, Compositing, WebGL, CacheStorage, DevTools, and Skia. Google confirmed an exploit exists but withheld technical detail to give users and dependent projects time to apply the fix. The flaw was reported by researcher Salvatore Gulizia, known online as "Serotav."
V8 compiles and runs the JavaScript on every page you visit, so a type confusion bug there can be triggered by a specially crafted web page and can lead to code execution inside Chrome's sandboxed renderer process. Fixed versions are 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux, arriving as a gradual rollout. This is the sixth actively exploited Chrome flaw Google has patched this year. Chromium-based browsers including Edge, Brave, Opera, and Vivaldi need the same attention and typically trail by a couple of days.
In short: Google patched CVE-2026-85046, an actively exploited type confusion flaw in Chrome's V8 engine, alongside eleven other vulnerabilities.
What it means for your business: This is a ten-minute task with real payoff. Have everyone open Settings, then About Chrome, let the update download, and restart the browser, because the fix does not take effect until that restart happens.
My take: Browser zero-days are the most democratic security problem there is. It does not matter what industry you are in or how many people you employ, everyone runs a browser, and a malicious page is about as low-effort a delivery mechanism as attackers get. The part people consistently get wrong is the restart. Chrome downloads the update quietly and then waits, sometimes for days, because nobody ever closes their tabs, which means a fleet that reports as updated in a dashboard can still be running the vulnerable build in memory. If you manage machines, force the relaunch. If you do not, tell your team to actually quit the browser today instead of letting it ride until the next reboot.
Source: Google warns of new Chrome zero-day flaw exploited in attacks, BleepingComputer
Attackers rerouted a developer platform's registry to hand out credential stealers
Coder disclosed that an attacker got into its Cloudflare infrastructure and added unauthorized IP addresses to the pool serving registry.coder.com, the site developers pull components from when building workspace templates. Cloudflare then routed a share of legitimate registry requests to the attacker's servers, which returned modified Terraform modules carrying credential-stealing code. The delivery window ran from 07:35 UTC to 21:45 UTC on Monday, August 31.
What those modules went looking for is close to comprehensive: provisioner environment variables and secrets, cloud infrastructure and AI tooling API keys, CI/CD credentials, configuration file secrets and terminal history, user OIDC tokens, configured SSH keys, one-time external authentication tokens, and Coder database passwords. The haul was sent to the lookalike domain coder-infra[.]com. Coder's user list includes Dropbox, Palantir, Square, Mercedes-Benz, KKR, and US government and defense organizations. Because the attacker's infrastructure sits outside Coder's control, the company says it cannot conclusively identify every compromised deployment, which puts the burden on operators to check their own firewall, proxy, DNS, and VPC flow logs and rotate secrets. Patched releases are 2.37.0, 2.36.4, 2.35.7, and 2.34.9.
In short: Attackers added rogue servers to Coder's registry infrastructure and served malicious Terraform modules that harvested cloud keys, CI/CD credentials, SSH keys, and OIDC tokens during a fourteen-hour window on August 31.
What it means for your business: If your developers or a contracted dev shop use Coder, treat every credential that touched a provisioner during that window as burned and rotate it, and do not wait for confirmation that you were affected, because the vendor has already said it cannot make that determination for you.
My take: This is the third supply chain incident in roughly a week where the compromise happened at the delivery layer rather than inside the code, and that pattern is the thing to internalize. Nobody backdoored a package. Somebody changed where the request went. Dependency pinning, code review, signature checks against the source repository, none of it helps when the server answering your request is not the server you think it is. The uncomfortable detail is Coder's own admission that it lacks the logs to tell customers whether they were hit. That is less negligence than physics, and it means the default response to any registry compromise should be to rotate first and investigate second.
Source: Coder's registry infrastructure compromised to push malicious modules, BleepingComputer
A WordPress page builder flaw is being used to plant webshells
Attackers are actively exploiting CVE-2026-32475 in Elementor Pro, the WordPress page builder with more than six million active installations. The flaw lives in how the plugin validates file upload arrays in its forms. Submit an empty file as the first array element and a malicious PHP file as the second, and the plugin stops validating everything that follows, dropping the payload into /wp-content/uploads/elementor/forms/ under a random filename where the attacker can request it directly and run commands on the server.
The timing is the ugly part. Elementor patched the flaw in version 4.2.2 on August 19, and Wordfence says exploitation began the same day. Since then its firewall has blocked close to 200,000 attempts against its own customers, with the heaviest activity between August 19 and 23. Versions 4.2.1 and earlier are affected, and exploitation only works when a site has a published Elementor Pro Form widget with at least one File Upload field, which is an extremely common setup for contact, quote, and job application forms.
In short: A critical Elementor Pro flaw, CVE-2026-32475, is under active attack to plant webshells on WordPress sites, with Wordfence blocking nearly 200,000 attempts since August 19.
What it means for your business: If your website runs WordPress with Elementor Pro, update to 4.2.2 or later today, then have someone look inside /wp-content/uploads/elementor/forms/, because a PHP file sitting in that folder is a strong indicator the site is already compromised.
My take: Small business websites are where this kind of thing quietly succeeds, because the site was built once by an agency three years ago and nobody has logged into the admin since. Six million installs and a contact form with a file upload field is about as ordinary a configuration as exists on the web. What makes this one worth acting on rather than filing away is that the check is concrete. You are not hunting for subtle evidence of intrusion, you are looking for a PHP file in a folder that should only ever hold form submissions. That is a five-minute answer for whoever maintains your site, and it is the difference between finding out now and finding out when your domain starts sending spam.
Source: Critical Elementor Pro flaw exploited to take over WordPress sites, BleepingComputer
The US is now the top target of a campaign that installs real IT software
A phishing operation first identified through its use of Canada Revenue Agency tax forms as bait turns out to be far broader, spanning 46 countries, with the United States now its single largest target at roughly 45% of observed activity. ANY.RUN connected 601 cases to the wider operation. The goal is not to steal a password. It is to convince the victim to install legitimate remote monitoring and management software, the same category of tool your IT provider uses, which then hands the attacker interactive access that looks entirely normal to security tooling.
The lures rotate to fit the target: shipping and UPS notices, Adobe PDFs, tax notices, US Social Security Administration themes, and invoices. The infrastructure rotates faster than the tactics, running on disposable Vercel deployments swapped out daily, which makes blocklisting a losing game.
In short: An RMM phishing campaign spanning 46 countries now aims primarily at US targets, tricking victims into installing legitimate remote management software through shipping, tax, and invoice lures.
What it means for your business: Decide now which remote support tool your company actually uses, write the name down, tell your staff, and make it a standing rule that any other remote access prompt gets refused and reported, because "an IT tool is installing itself" is not something your antivirus is going to flag.
My take: This is the attack I would bet on reaching a small business this quarter, ahead of anything involving a CVE. There is no exploit, no zero-day, no unpatched server. Somebody receives an invoice that looks real, installs what they are told to install, and the software is genuinely legitimate, which is precisely why nothing blocks it. The defense here is organizational rather than technical. If your team knows the company uses one specific remote support tool and nothing else, ever, the whole category collapses into an easy judgment call. If they do not know, every RMM installer looks equally plausible, and infrastructure that rotates daily means a blocklist will not save you.
Source: US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries, The Hacker News
A regulator fined a hospital 500,000 euros and published the checklist it failed
France's data protection authority fined Hôpital privé de la Loire 500,000 euros, about $580,000, over a summer 2025 breach that exposed data on 524,867 patients and another 202,246 people designated as trusted third parties, more than 727,000 people in total. A teenage hacker using the alias "Marak" claimed responsibility and said the intrusion started with a single compromised doctor's account.
The CNIL's list of failures reads like a checklist, and none of it is exotic. External users including private-practice physicians could reach the electronic patient record system without a VPN or multi-factor authentication. Access controls were loose enough that one compromised account could pull records for every patient in the hospital. There was no real-time or near-real-time monitoring and alerting, so the attacker explored the system and extracted a large volume of data over several days without detection. And the hospital notified affected patients but never directly told the 202,246 third parties whose data was also taken. The cited violations fall under GDPR Articles 32 and 34.
In short: France's CNIL fined a private hospital 500,000 euros after one compromised doctor's account exposed data on more than 727,000 people, citing missing multi-factor authentication, weak access controls, no monitoring, and incomplete notification.
What it means for your business: The regulator did not fine this hospital for being breached, it fined it for four specific controls that were missing, and three of those four cost very little to put in place.
My take: Enforcement stories are more useful than breach stories, because they tell you what somebody with actual authority decided the minimum was. Strip away the healthcare context and the findings are completely generic: remote access without multi-factor authentication, an account that could read everything, nobody watching, and notification that skipped a third of the affected people. That describes a lot of small companies I have looked at. The finding that gets underrated is monitoring. Multi-factor authentication and least privilege get the attention because they are things you can buy, but the reason this became 727,000 records instead of a handful is that the attacker had several unobserved days to work. Detection is what turns a bad login into a small incident, and it is almost always the last thing anyone gets around to.
Source: French hospital fined €500,000 after breach exposes data of 727,000, BleepingComputer
🧰 New tooling for builders and business
GitHub reopened Copilot Business signups, and changed how you pay
GitHub said on Thursday it is gradually reopening signups for Copilot Business and Copilot Enterprise over the next couple of weeks for customers paying by credit card or PayPal, while strengthening account vetting at the same time. Availability is rolling out in stages, so a plan that is not purchasable today may be next week.
The billing change underneath is the part worth noting. New Copilot Business and Enterprise seat assignments will require payment for each seat before users gain access, and starting October 1, 2026, existing card and PayPal customers will see an upfront charge for all assigned seats at the start of each billing cycle. Included usage may be prorated across the month to align with seat cost proration, and exceeding your included usage may require additional payment before you and your users can continue. Plan pricing itself is not changing, and neither is the ability to buy usage beyond your included allowance.
In short: GitHub is reopening Copilot Business and Enterprise signups with tighter account vetting, and moving credit card and PayPal customers to upfront per-seat charges starting October 1, 2026.
What it means for your business: If you pay for Copilot by card, your October invoice will arrive earlier in the cycle and cover every assigned seat, which makes this a good week to reclaim seats from people who are not using them.
My take: Reopened signups plus stricter vetting plus pay-before-access is the standard shape of a company that got hammered by fraudulent accounts and abusive usage, and fixing that is reasonable. The part that will actually irritate legitimate customers is upfront per-seat charging, because it removes the float that made it painless to leave a few extra seats assigned just in case. Practically, this rewards housekeeping. Pull the seat list, find the people who got assigned Copilot during an enthusiastic rollout and have not opened it since, and unassign them before October 1. That is a real line item, and it is exactly the kind of task nobody gets to until the billing model makes it visible.
Source: Reopening Copilot Business and Enterprise signups, GitHub Changelog
Four models leave GitHub Copilot on October 2
GitHub also announced that four models will be removed from every Copilot experience on October 2, 2026, including Copilot Chat, inline edits, ask and agent modes, and code completions. Going away are Gemini 3.5 Flash and Gemini 3.6 Flash, both pointed at Gemini 3.8 Flash as the replacement, Kimi K2.7 Code, pointed at Kimi K3, and Claude Opus 4.7, pointed at Claude Opus 5. Gemini 3.8 Flash arrived in Copilot the same day.
No action is required to remove the models themselves, but workflows and integrations that name a specific model will break, and Copilot Business and Enterprise administrators may need to enable the replacement models through their model policies in Copilot settings first. That second point is the one that catches teams out, because a successor model does not appear in the Copilot Chat model selector until an administrator has switched the policy on.
In short: GitHub is retiring Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7 from Copilot on October 2, 2026, with a named successor for each.
What it means for your business: Anyone with automations or scripts that pin a specific Copilot model has about four weeks to repoint them, and administrators should enable the replacement models in Copilot settings now so the cutover does not strand users on a missing option.
My take: The recurring lesson of the past year is that model names are not stable infrastructure, and treating them as such creates small, entirely avoidable outages. Four weeks of notice is generous by the standards of this industry, and the migration path is spelled out model by model, which is more than you usually get. The trap is the admin policy step. Nothing in your organization will look broken until October 2, when a developer opens the model picker, finds their model gone and the replacement not enabled, because turning it on was somebody else's job that never got assigned. Do that part this week. It takes minutes, and it is the only piece of this with a dependency on a human remembering.
Source: Upcoming deprecation of selected GitHub Copilot models, GitHub Changelog
That is the AI and IT news that matters for September 4, 2026. Have a question about how any of this hits your business? Reach out to the KeyChange team, and check back Monday for the next recap.