OpenAI Launches GPT-6 Astra Ultrafast on NVIDIA Blackwell, Publishes a Practical Guide to Building with GPT-6, and Google’s Suncatcher AI-in-Space Satellite Reaches Orbit

This brief covers the trailing ~72 hours (October 1–4, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. It was a quiet window after a busy week of model launches: OpenAI’s fastest GPT-6 tier arrived on NVIDIA Blackwell, OpenAI published developer guidance for the GPT-6 family and a retail deployment with Albertsons, and Google’s first Project Suncatcher satellite launched.

OpenAI launches GPT-6 Astra Ultrafast, running up to 8x faster on NVIDIA Blackwell

NVIDIA · October 1, 2026

NVIDIA says OpenAI’s GPT-6 Astra Ultrafast delivers up to 8x faster token generation than standard mode on NVIDIA Blackwell GPUs. The speedup comes from continuous inference optimizations aimed at code generation, tool use, and interactive applications. OpenAI used its own models to help refine the inference software, which NVIDIA presents as an example of programmable hardware improving after deployment.

“Our work with NVIDIA is helping us make AI faster and more useful.” — Uday Ruddarraju, Chief Technology Officer of Compute, OpenAI

Source: How NVIDIA GPUs Help Accelerate OpenAI’s GPT-6 Astra Ultrafast

OpenAI publishes a practical guide to building with the GPT-6 family

OpenAI · October 2, 2026

The guide gives developers strategies for choosing among GPT-6 models, tuning prompts, handling long-running tasks, and preparing workflows for production while balancing capability, cost, and latency. A recurring theme is that newer models need less rigid prompting than earlier generations.

“Models have gotten much better at understanding nuance and ambiguity, so overly specific guidance can now hinder results.” — Eric Provencher, Developer Experience, OpenAI

Source: A practical guide to building with GPT-6

Google’s Project Suncatcher prototype satellite launches to test TPUs in orbit

Google · October 1, 2026

Google’s prototype satellite for Project Suncatcher, built with Planet, launched aboard SpaceX’s Transporter-18 mission. It will gather data on how TPUs perform under spaceflight conditions, including extreme radiation and thermal environments, to test whether machine learning infrastructure can run in space.

“This is the first step in a long-term research moonshot exploring whether space could one day host scalable machine learning infrastructure.” — Travis Beals, Senior Director, Paradigms of Intelligence, Google

Source: Project Suncatcher prototype satellite is in orbit

Albertsons expands OpenAI use across 2,200+ stores and launches a Safeway experience in ChatGPT

OpenAI · October 1, 2026

Albertsons Companies is expanding its use of ChatGPT Enterprise and the OpenAI API across its stores. Shoppers can now plan meals and build carts through a new Safeway experience inside ChatGPT, while merchants get recommendations and promotional insights that combine predictive models with generative AI.

“This is another practical way we are using AI to reduce friction and make everyday shopping easier.” — Jill Pavlovich, SVP, Digital Customer Experience, Albertsons Companies

Source: How Albertsons Companies is reimagining retail from the inside out


This brief covers the trailing ~72 hours (October 1–4, 2026).

Primary sources:

FortiMail Path-Traversal Zero-Day, Zammad Zero-Days Hit KEV, and Critical Fortra BoKS Auth Bypass

This brief covers security developments disclosed between October 1 and October 3, 2026. Every item below was checked against its primary source: the vendor advisory, the CISA KEV alert, or the original research.

Fortinet FortiMail zero-day lets unauthenticated attackers write arbitrary files (CVE-2026-104286)

Fortinet PSIRT · October 1, 2026

Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal and NULL-byte handling flaw in FortiMail. An unauthenticated attacker can use crafted HTTP/HTTPS requests to write arbitrary files on the system, which can lead to code execution. FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9 are affected. The bug is actively exploited and the fixed releases (8.0.2, 7.6.7, 7.4.9) are still listed as “upcoming.” Until they ship, Fortinet’s workaround is to disable IBE or keep the webmail interface off the internet. CISA added it to KEV on October 1 with an October 4 deadline for federal agencies. Fortinet also published IOCs, including the IPs 79.141.169[.]187 and 45.129.0[.]192.

“This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” — Fortinet, FG-IR-26-175

Source: Fortinet FG-IR-26-175 · CISA KEV alert · The Hacker News

Zammad zero-days used in AI-agent breach of DIVD added to KEV (CVE-2026-102489, CVE-2026-102490)

DIVD CSIRT / CISA · October 2, 2026

CISA added two Zammad helpdesk flaws to KEV on October 2. Both were exploited as zero-days in the September 21 breach of the Dutch Institute for Vulnerability Disclosure (DIVD), which DIVD describes as an agentic-AI-driven attack. CVE-2026-102489 (CVSS 9.4) is a session fixation/hijack bug that leads to RCE as the zammad user. It affects Zammad 6.3.0–6.5.4. Versions 7.0.0–7.1.3 contain the bug, but it isn’t exploitable there because of environment conditions. CVE-2026-102490 (CVSS 9.4) is a local privilege escalation to root that affects all versions. Neither flaw had a fix at disclosure. DIVD has published an IOC log-check script.

“We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” — DIVD CSIRT

Source: DIVD-2026-00015 · CISA KEV alert · SecurityWeek

Fortra patches three critical BoKS flaws, including AD service-account auth bypass

Fortra · October 1, 2026

Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS). Three of them are critical:

  • CVE-2026-79901 (CVSS 9.9): AD service-account passwords are generated from a predictable sequence seeded with the Unix timestamp, which allows an authentication bypass.
  • CVE-2026-79898 (CVSS 9.1): command injection in crlserver that runs as root on the BoKS Master.
  • CVE-2026-12627 (CVSS 9.8): a stack overflow in autoregistration.

Patches are available. Fortra has not reported in-the-wild exploitation, and none of the three is in KEV.

“An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.” — Fortra

Source: Fortra product security advisories · SecurityWeek

Still developing

Cisco Catalyst SD-WAN Manager auth bypass exploited as zero-day (CVE-2026-76504)

Cisco PSIRT · September 30, 2026

CVE-2026-76504 (CVSS 9.8) is an API authentication bypass caused by improper URI-encoding handling. It gives unauthenticated attackers admin-level API access to Catalyst SD-WAN Manager. All deployments are affected regardless of configuration, and there is no workaround. Fixes are in 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1. CVE-2026-76504 is actively exploited and in KEV, with a federal deadline of October 3. Cisco published IOCs for serviceproxy-access.log and vmanage-server.log.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” — Cisco

Source: Cisco advisory · CISA KEV alert · SecurityWeek

Citrix NetScaler exploitation: post-exploitation payloads create superuser and hide web shells (CVE-2026-88771)

LevelBlue SpiderLabs · October 1, 2026

LevelBlue documented exploitation of CVE-2026-88771 (CVSS 9.5), a pre-auth command injection in NetScaler ADC and Gateway that is already in KEV, across multiple customer environments. In some cases a Perl payload added a “sec_monitor” superuser and exfiltrated /flash/nsconfig. Attackers also planted PHP web shells mapped to URLs that look like CSS resources. Separately, Mandiant/GTIG reported dozens of victims of the companion bug, CVE-2026-88772.

“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation.” — LevelBlue

Source: LevelBlue · CISA alert · The Hacker News

Microsoft: Zimbra SNMP command injection was probed before public disclosure (CVE-2026-73570)

Microsoft Threat Intelligence · September 30, 2026

CVE-2026-73570 (CVSS 8.9) is an unauthenticated OS command injection in Zimbra Collaboration Suite. It can be triggered through crafted SMTP traffic when zimbra-snmp is installed and SNMP notifications are enabled. Microsoft says scanning of the vulnerable code path started between the July 20 patch (ZCS 10.1.20) and the August 13 public disclosure. Later attacks deployed JSP web shells, escalated to root and stole credentials. The fix is ZCS 10.1.20 or later.

Source: Microsoft Security Blog · SecurityWeek


This brief covers the trailing ~48 hours (October 1–3, 2026).

Primary sources:

Google Unveils Gemini 4 Argon, OpenAI Ties a Distillation Campaign to Moonshot AI, and Anthropic Commits $100M to Train 10,000 Engineers

This brief covers the trailing ~72 hours (September 30–October 3, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Google announced Gemini 4 Argon, its new frontier model, with access initially limited to trusted cyber defenders. OpenAI disclosed that it disrupted a large campaign to extract protected model reasoning and attributed a core cluster to individuals associated with Moonshot AI. Anthropic launched a $100 million academy to train enterprise AI engineers, expanded its partnership with Barclays, and published a guest essay on “Claude-shaped” science.

Google announces Gemini 4 Argon, starting with trusted cyber defenders

Google · September 30, 2026

Gemini 4 Argon is Google’s new frontier model for long-horizon coding, enterprise knowledge work such as legal and finance, and cyber defense. Google reports a state-of-the-art 77.9% on DeepSWE v1.1, the top spot on the Vals Index, 51.3% on Zapier’s AutomationBench, and 91.7% on LVBench. The output token limit rises to 1 million, up from 64K. Argon is rolling out first to defenders in Google’s Fairwind Program, without cyber guardrails for those vetted users, while Google takes part in the U.S. government’s voluntary pre-release access process. Broader availability will start with paid API customers and Google AI Ultra subscribers. The introductory price is $2/$10 per million input/output tokens, rising to $4/$20 after the introductory period.

“Built to sustain deep reasoning across complex, long-horizon workflows, Argon is fundamentally changing the way we work and build at Google.” — Koray Kavukcuoglu, SVP, Google DeepMind

Source: Gemini 4 Argon: our next era of frontier intelligence

OpenAI disrupts a coordinated model-distillation campaign and attributes a core cluster to Moonshot AI

OpenAI · September 30, 2026

OpenAI says operators manipulated model interactions to get protected reasoning reproduced in visible form. One technique was copying encrypted reasoning from one conversation and asking a model in another to decrypt it. The activity began July 1 and spiked on July 24–25 with 16,000 attempted extraction requests from more than 4,000 users. A related cluster of more than 15,000 users was fully disrupted by July 28. OpenAI says no encryption or databases were breached. It closed the reasoning-replay pathway, banned accounts, and shared findings through the Frontier Model Forum and government channels.

“we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.” — OpenAI

Source: Disrupting a coordinated model-distillation campaign

Anthropic launches Claude Frontier Academy with $100M to train 10,000 deployed engineers

Anthropic · October 2, 2026

The Academy’s first program, the Frontier Deployed Engineer Residency, starts with a multi-day in-person program that ends in a graded practical. A 12-week residency follows, in which each engineer leads a real Claude project at their own organization. The goal is 10,000 certified engineers by the end of 2027. First cohorts are running in San Francisco, New York, and London, with engineers from Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley, and Novo Nordisk. Participation is by nomination.

“Claude Frontier Academy trains people the way our own engineers learn” — Steve Corfield, Global Head of Business Development and Partnerships, Anthropic

Source: Anthropic invests $100 million to train 10,000 engineers and tackle the enterprise AI talent gap

Barclays scales Claude across the bank, targeting 50% Claude Code adoption among developers this year

Anthropic · October 1, 2026

Barclays is extending its collaboration with Anthropic to speed up software development and modernize legacy systems. It expects Claude Code to reach half of its developers by the end of 2026 and most of its software engineers in 2027. Existing deployments include a Claude-powered Colleague Knowledge Assistant used by more than 16,000 Barclays UK staff, with over one million searches. In Global Markets, Claude helps classify and route about 120,000 client emails a day.

“Claude now helps 16,000 Barclays’ colleagues find answers for customers, sorts 120,000 emails a day, and will be in the hands of most Barclays engineers by 2027.” — Paul Smith, Chief Commercial Officer, Anthropic

Source: Barclays scales Claude to upgrade operations and improve client experience

“Claude-shaped science”: physicist Matthew Schwartz open-sources BootLoops after 36 manuscripts across 18 fields

Anthropic · October 1, 2026

In a guest post, physicist Matthew Schwartz describes picking problems suited to what current models do well instead of treating Claude like a human scientist. That approach produced BootLoops, an open-source harness for exact calculations in quantitative science. Starting from scattering amplitudes, where it computed 15 previously uncomputed elliptic Feynman integrals, the work spread to ecology, population genetics, economics, linguistics, and other fields with domain experts steering. Schwartz says Claude’s first findings in other fields were often technically correct but scientifically unremarkable until experts redirected them. He also lists failure modes such as declaring victory too early. Schwartz is a visiting researcher at Anthropic; BootLoops is his own project.

“Claude and GPT are good at science, but they are not scientists” — Matthew Schwartz

Source: Claude-shaped science

Still developing

Anthropic releases Claude Sonnet 5.5 (September 28, 2026). This is the second model in the Claude 5.5 family. Anthropic reports 70.6% on Terminal-Bench 4.0 and a GDPval-AA score within two points of Opus 5.5, at unchanged pricing of $2/$10 per million tokens. It is the first Sonnet to launch with cyber safeguards and classifiers that block reasoning extraction. Haiku 5.5 is due in the coming weeks. “It’s a clear upgrade over Claude Sonnet 5, runs 30%+ faster, and costs up to 30% less for most work.” — Anthropic. Source: Introducing Claude Sonnet 5.5

OpenAI ships GPT-6.1 Sol (September 29, 2026). OpenAI says this upgrade to GPT-6 Sol matches GPT-6 Astra on DeepSWE v1.1 at roughly one-fifth the cost. Prices are $2/$10 per million tokens, with cached input cut to $0.10. It is available in ChatGPT Work, Codex, and the API as gpt-6.1-sol. OpenAI says it “nearly matches GPT-6 Astra’s intelligence on agentic coding, computer use, and professional work at one-fifth of Astra’s standard input and output token prices.” Source: Introducing GPT-6.1 Sol


This brief covers the trailing ~72 hours (September 30–October 3, 2026).

Primary sources:

Unpatched Citrix NetScaler RCE Zero-Days, SharePoint and MikroTik RouterOS Flaws Hit CISA KEV, ShinyHunters Bypasses WAFs in Oracle PeopleSoft Attacks

This brief covers September 25–27, 2026. Each item was checked against its primary source (CISA’s KEV alert, the vendor advisory, or the original research), with reputable outlets linked for context. Two things lead this window: a warning of unpatched Citrix NetScaler zero-days under active exploitation, and a CISA KEV update covering Microsoft SharePoint and MikroTik RouterOS.

Two unpatched Citrix NetScaler RCE zero-days reported exploited in the wild

watchTowr · September 26, 2026

On September 26, watchTowr said two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were exploited before any fix existed, and that the exploitation was found during forensic investigations. As of Sunday morning Citrix had published no bulletin, CVE IDs, CVSS scores, workarounds, or IOCs, and no CVE is in KEV. watchTowr expects Citrix communications and patches early in the week of September 28. These are separate from the August authentication bypass CVE-2026-19490. Some administrators have taken appliances offline. Because the exploitation came before any patch, installing the fix will not show whether a device was already compromised. Citrix’s existing guidance for suspected compromise (preserve evidence, isolate the appliance, rotate secrets and certificates) is the relevant playbook until then.

“While details are scarce, the information is credible.” (watchTowr, via X)

Source: The Hacker News · Citrix compromise guidance (CTX694799)

CISA adds exploited SharePoint code injection and MikroTik RouterOS flaws to KEV

CISA / Microsoft MSRC · September 25, 2026

CISA added two entries to the KEV catalog. CVE-2026-65660 (CVSS 8.8) is a code injection flaw in SharePoint Server 2016, 2019, and Subscription Edition. It lets an authenticated low-privilege attacker execute code over the network. Microsoft patched it in August and first classified it as spoofing, then reclassified it as RCE. Previdian saw exploitation attempts starting September 24, after Viettel Security published technical details. CVE-2026-67279 (CVSS 6.9) is a RouterOS flaw that lets an unauthenticated client open a session channel and send an exec request. Chained with CVE-2026-86060 (already in KEV) in the “MikroTrick” exploit, it gives unauthenticated administrative control of exposed routers, according to CERT Polska. Both have fixes available, and the SharePoint deadline for federal agencies is September 28.

“As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.” (Microsoft MSRC advisory)

Source: CISA alert · MSRC CVE-2026-65660 · SecurityWeek · The Hacker News

ShinyHunters resumes mass exploitation of Oracle PeopleSoft with a one-character WAF bypass

Mandiant / Google Threat Intelligence Group · September 25, 2026

Mandiant and GTIG report a new wave of attacks by UNC6240 (ShinyHunters) exploiting CVE-2026-35273 (CVSS 9.8), an unauthenticated Java deserialization RCE in PeopleSoft’s Environment Management Hub (PSEMHUB). Oracle patched it in June. The attackers request /%50SEMHUB/ instead of /PSEMHUB/, which slips past WAF rules that match the literal path before URL decoding. They are targeting organizations that deployed WAF rules but never patched. Web shells (x.jsp, u.jsp) were found on dozens of systems in higher education, technology, healthcare, government, and other sectors, along with the SIDEEYE backdoor, Neo-reGeorg tunnels, and MeshAgent. Mandiant’s advice: apply Oracle’s patch, disable or remove EMHub, and enforce blocking on the normalized path.

“WAF rules and path-based blocking are not a substitute for patching.” (Mandiant)

Source: Google Cloud Threat Intelligence · Oracle Security Alert · BleepingComputer

Kiteworks tells customers to shut down servers after a law-enforcement warning of an imminent attack

Kiteworks · September 25, 2026

Kiteworks, the secure file-sharing vendor formerly known as Accellion, told customers worldwide to take their systems offline for a six-hour window on Saturday, September 26. The company said federal authorities had warned that a threat actor might target Kiteworks systems. Kiteworks says it knows of no compromise and that all known vulnerabilities are fixed in version 9.5.1. It has not confirmed a zero-day, and no CVE has been assigned. Managed file transfer platforms have a long history as targets for data-theft extortion.

“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach.” (Kiteworks statement to BleepingComputer)

Source: BleepingComputer · The Hacker News

Compromised Mini Shai-Hulud GitHub Actions came back online still serving malware

Socket · September 25, 2026

Socket found that two GitHub Actions compromised in the May 2026 Mini Shai-Hulud supply-chain campaign, actions-cool/issues-helper and actions-cool/maintain-one-comment, became accessible again on September 16. Their release tags still pointed to the malicious commits, so any workflow that referenced them by tag ran the payload again. GitHub has disabled both repositories a second time. Teams that use either action should audit recent workflow runs, rotate any CI secrets those runs could reach, and pin actions to full commit SHAs.

“On September 16, 2026, both repositories became accessible again.” (Karlo Zanki, Socket)

Source: The Hacker News · BleepingComputer


This brief covers the trailing ~48 hours (September 25–27, 2026).

Primary sources:

WordPress Core RCE Under Active Exploitation, WSO2 and Adobe Commerce Added to KEV, TeamCity Flaw Tied to Ransomware

This brief covers security developments from September 23–25, 2026. Every item was checked against the vendor advisory, the CISA KEV catalog, or the original research, with reputable outlets linked for context.

Attackers move from probing to payloads on WordPress core flaw CVE-2026-87902

WordPress / Patchstack · September 23, 2026

CVE-2026-87902 is an unauthenticated path traversal flaw in WordPress core page-template resolution. It affects versions 4.7.0 through 7.1.1, and the WordPress security team rates it critical (CVSS v4.0 9.2). WordPress 7.1.2 fixed it on September 22, and the fix was backported to every branch down to 4.7. Patchstack saw reconnaissance start within hours of the patch. By September 23, traffic had grown tenfold and included pearcmd.php-based payloads that write PHP files to /tmp and /var/tmp. Remote code execution requires specific theme and server conditions, such as a theme directory whose name starts with page- and PHP’s register_argc_argv setting being enabled. None of the sources reviewed reported a CISA KEV listing.

“Because this is a security release, it is recommended that you update your sites immediately.” — WordPress.org, 7.1.2 release notes

Source: WordPress 7.1.2 Release · GHSA-7hp8-65ch-5whp · BleepingComputer

CISA adds WSO2 API Manager auth bypass CVE-2026-5430 to KEV

CISA / WSO2 · September 24, 2026

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. Federal agencies must patch by September 27. WSO2’s advisory scores the flaw CVSS 3.1 10.0, or 9.8 in single-tenant deployments. It describes a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, which can lead to takeover of administrative accounts. CISA’s KEV entry calls it a path traversal. Affected products are WSO2 API Control Plane 4.5.0–4.6.0, API Manager 4.1.0–4.6.0, Traffic Manager 4.5.0–4.6.0, and Universal Gateway 4.5.0–4.6.0. watchTowr reported in-the-wild attempts against its honeypots since at least September 13.

“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.” — WSO2 Security Advisory WSO2-2026-5328

Source: WSO2-2026-5328 · CISA alert · The Hacker News

Adobe Commerce / Magento session-switching flaw CVE-2026-71362 added to KEV

CISA / Adobe · September 24, 2026

CISA added CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento Open Source (CVSS 9.1), to the KEV catalog in the same September 24 update. The federal remediation deadline is September 27. The bug lets an unauthenticated attacker switch a customer session to another customer’s account. Sansec reported blocking exploitation attempts in August, shortly after Adobe’s APSB26-92 fix. Adobe has not yet updated its advisory to confirm exploitation. The fix is to install the -2026-aug security release or the APSB26-92 isolated patch.

“The vulnerability lets attackers switch a customer session to another customer account.” — Sansec

Source: CISA alert · Sansec research · The Hacker News

CISA marks JetBrains TeamCity CVE-2026-63077 as used in ransomware campaigns

CISA / JetBrains · September 23, 2026

CISA updated the KEV entry for CVE-2026-63077 to show that it is “Known” to be used in ransomware campaigns. The flaw is a critical authentication bypass in TeamCity On-Premises that JetBrains patched on July 25 in versions 2025.11.7 and 2026.1.3. It allows unauthenticated OS command execution through the agent polling protocol. The CVE was first added to KEV on August 5. Shadowserver still tracks about 160 unpatched internet-exposed servers.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands.” — JetBrains

Source: CISA KEV entry · JetBrains update · BleepingComputer

Still developing

Check Point confirms exploitation of Security Gateway VPN RCE and a Management Server zero-day

Check Point · September 22, 2026

Check Point Research confirmed exploitation of two flaws, both rated CVSS 9.8. The first, CVE-2026-85102, is a pre-authentication RCE in Security Gateway and Spark VPN certificate handling. It was patched September 9, and exploitation attempts against Spark customers started September 12. The second, CVE-2026-93616, is a pre-authentication path traversal zero-day in the Management web service that allows arbitrary script execution and Java class loading. It was used in a handful of targeted attacks on July 23 and is fixed via sk1000171. CISA added both to KEV on September 22 with a September 25 due date.

“Customers running affected versions should install the applicable fixes immediately.” — Lotem Finkelstein, Check Point Research

Source: Check Point advisory · sk1000117 · sk1000171 · BleepingComputer

F5 BIG-IP APM OAuth Authorization Server zero-day CVE-2026-94127

F5 · September 22, 2026

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM (CVSS 3.1 9.8 / CVSS 4.0 9.3). Unauthenticated attackers can get RCE when APM is configured as an OAuth Authorization Server. F5 confirmed in-the-wild exploitation and published indicators of compromise plus an iRule mitigation. CISA added the flaw to KEV on September 22. Shadowserver sees roughly 14,700 IPs with BIG-IP APM fingerprints.

“We have learned that this vulnerability has been exploited.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

ShinyHunters claims FBI breach via unpatched Oracle PeopleSoft zero-day

BleepingComputer · September 22, 2026

The ShinyHunters extortion group claims it used a new Oracle PeopleSoft RCE zero-day to reach FBI systems and FBI-managed AWS GovCloud infrastructure. It says it stole 2–3 TB of employee and applicant data. The FBI says it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov” but has not confirmed a breach. Oracle has not published an advisory or CVE, and the zero-day has not been independently verified.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 23–25, 2026).

Primary sources:

Anthropic Launches Claude Opus 5.5, OpenAI Ships GPT-6 Sol and Luna at Half Price, and Claude Agents Find a CRISPR-Like Enzyme System

This brief covers the trailing ~72 hours (September 22–25, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Two frontier releases landed on the same day: Anthropic introduced Claude Opus 5.5, the first model in its Claude 5.5 family, and OpenAI extended its GPT-6 generation downmarket with GPT-6 Sol and GPT-6 Luna at 50% lower API prices. Anthropic also unveiled a life sciences lab and early results in which Claude agents found a previously unrecognized enzyme system. At the UN, Sam Altman addressed the Security Council and OpenAI extended its Daybreak cyber-defense program to Ukraine, and Google added real-time video avatars to Gemini 3.8 Live.

Anthropic introduces Claude Opus 5.5: Fable 5.1-level performance at 40% lower cost than Opus 5

Anthropic · September 22, 2026

Opus 5.5 is the first model in the Claude 5.5 family and Anthropic’s first release since it called for “pacing the frontier.” Anthropic reports 66.4% on Terminal-Bench 4.0, 54.4% on FrontierCode v1.1, 57.8% on CursorBench 4.0, and a GDPval-AA v2.1 Elo of 1846, ahead of Fable 5.1, Opus 5, and GPT-6 Astra on most of those measures. Pricing drops to $4/$20 per million input/output tokens with cache reads at $0.20 (60% below Opus 5), output is over 30% faster, and the model scored best to date on Anthropic’s automated behavioral audit. Because its biology and cyber capabilities are comparable to Claude Mythos 5.1, it ships with Fable 5.1-class safeguards that transparently fall back to other models; Sonnet 5.5 and Haiku 5.5 are due in the coming weeks.

“It performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.” — Anthropic

Source: Introducing Claude Opus 5.5

OpenAI releases GPT-6 Sol and GPT-6 Luna, cutting API prices 50% versus GPT-5.6

OpenAI · September 22, 2026

OpenAI expanded the GPT-6 family with two cheaper tiers trained with methods similar to GPT-6 Astra. GPT-6 Sol is priced at $2/$10 per million input/output tokens and GPT-6 Luna at $0.10/$0.50, both half the GPT-5.6 promotional prices. OpenAI reports Sol scoring 33.2% on Zapier’s AutomationBench at $0.27 per task and 68.8% on DeepSWE v1.1, and says Sol makes about half as many factual mistakes as its predecessor on its internal evaluation. The launch also brings improved prompt caching with 90% discounts on cached reads and cache-preserving changes to reasoning effort and tools; the models are live in ChatGPT Work, Codex, and the API as gpt-6-sol and gpt-6-luna.

“GPT-6 Astra introduced a new generation of intelligence—these models help distribute the benefits of that intelligence by advancing the frontier on cost efficiency.” — OpenAI

Source: Introducing GPT-6 Sol and Luna

Claude agents discover a novel enzyme system with CRISPR-like repeats as Anthropic unveils a life sciences lab

Anthropic · September 23, 2026

Anthropic introduced a new life sciences research group and Bay Area wet lab focused on AI-driven genome mining. In its first reported result, roughly 950 Claude agents spent 21 hours and 210 million tokens surveying over 200,000 reverse transcriptases, narrowing 3,500 candidate systems to 20 detailed reports. One agent spotted a tandem repeat array next to an unusual RT in jumbo phages, a system Anthropic calls array-associated reverse transcriptases (ART). Initial lab experiments show the array is expressed as distinct short RNAs, suggesting a possibly programmable mechanism; its function is still under investigation, and a pre-print has been released.

“This is an exciting example of how AI agents can contribute to biological discovery.” — Feng Zhang, MIT and the Broad Institute

Source: Claude discovers a novel enzyme system with CRISPR-like repeats

Sam Altman addresses the UN Security Council, calling for international frontier AI standards

OpenAI · September 23, 2026

In remarks to the Security Council, Altman named two failure modes to avoid: losing control of the future to AI, especially as systems approach recursive self-improvement, and excessive concentration of power. He said OpenAI has unilaterally slowed down before and will again, and called for complementary national and international frontier AI standards covering capability measurement, risk assessment, safeguard sufficiency, incident reporting, and secure channels for sharing emerging threats, without locking in incumbents.

“Beating companies in a competitive pace is not a reason to make rash decisions.” — Sam Altman, OpenAI

Source: Sam Altman’s remarks at the United Nations Security Council

OpenAI extends its Daybreak cyber-defense program to the Government of Ukraine

OpenAI · September 23, 2026

Announced on the sidelines of the UN General Assembly, the arrangement with Ukraine’s Ministry of Digital Transformation gives Ukrainian teams access to OpenAI’s Daybreak tools for finding software vulnerabilities and developing and testing fixes to protect civilian infrastructure. OpenAI noted its cyber models are already used by defenders in France, Germany, and Poland, and by the EU cyber agency ENISA, and that CERT Polska used them to help find six vulnerabilities in third-party router software.

“Ukraine is already on the front line, and its defenders need support now.” — Sasha Baker, Head of National Security Policy, OpenAI

Source: OpenAI extends cyber access to Ukraine for civilian defense

Google adds Live Avatar to Gemini 3.8 Live for real-time, lip-synced video agents

Google · September 24, 2026

Google paired its Gemini 3.8 Live native dialogue model with low-latency streaming video, producing enterprise agents that listen, see, and speak through an animated persona with lip-sync and facial expressions. The feature supports asynchronous tool calling so the avatar keeps talking while fetching data in the background, switches among 97 languages mid-conversation, and can generate custom avatars from a reference image for allowlisted enterprises. All audio and video output is watermarked with SynthID, and the feature is available now in Gemini Enterprise.

“Starting today, Gemini 3.8 Live with Live Avatar is available in Gemini Enterprise.” — Google

Source: Introducing Gemini 3.8 Live with Live Avatar


This brief covers the trailing ~72 hours (September 22–25, 2026).

Primary sources: