Workaholic Developers

No. 2

Today's briefing

The attacker's hourly rate just fell

Anthropic says its Claude model broke into three companies during controlled security tests. The lesson for small businesses is boring, cheap and overdue.

8 stories Sourced from STLtoday.com, Hacker News, the-decoder.com, How-To Geek and others
Abstract illustration accompanying The attacker's hourly rate just fell
Abstract illustration, generated with AI. It represents the idea, not the event.

The one that matters

Anthropic says its own AI broke into three companies during security tests

STLtoday.com ↗

What happened, in plain words. Anthropic, the company that makes the Claude AI model, said that during cybersecurity testing its model was able to break into three companies' systems. The published accounts describe this as testing rather than a live attack in the wild. More than a hundred outlets carried the story within two days, and a few of them dressed it up as the AI "losing control." That is not what a test result shows. What it shows is that a machine, given an objective, worked through the whole tedious sequence of a break-in without a human doing the tedious part.

What it actually means for your business

The news is not that a computer can break into a network. Skilled people have done that for thirty years. The news is about labour cost. A competent intrusion has always meant days of dull work: mapping what a company runs, trying old passwords, finding the one forgotten server nobody patched, waiting. That dullness is the reason criminals have historically gone after banks and large exporters rather than a 600-student school in Nashik or a 30-bed clinic in Kitchener. You were not safe because you were well defended. You were safe because you were not worth the hours.

If the dull hours get cheap, the arithmetic changes, and it changes for exactly the businesses that assumed they were too small to bother with. A 600-student school holds 600 families' phone numbers, home addresses, fee records and bank mandates. A 30-bed clinic holds diagnoses. A workshop with 40 staff holds payroll data and a current account with real money moving through it every Friday. None of that was ever uninteresting to a criminal. It was just not worth a week of someone's time.

The same cost drop applies to the far more common attack you will actually meet: a convincing email. Fluent Gujarati, fluent Quebec French, correct GST terminology, your supplier's actual tone, sent the same week you really are expecting an invoice from them. That is the version most likely to cost you money this year.

What it does not mean, and who is overstating it

It does not mean AI systems are out there choosing targets on their own. This was testing. It does not mean your existing precautions are obsolete. Nearly every real breach at a business your size still comes in through the same four doors it always did: a reused password, no two-factor login, an unpatched server, and an ex-employee's account that was never switched off. An AI-assisted attacker walks through those doors faster. It does not need new ones.

Expect this headline to appear in sales decks within a fortnight. If a vendor quotes it while proposing an "AI-powered" security subscription at several times what you pay now, ask them plainly which of those four doors their product closes, and what it costs to close the same door without them. Be especially wary of anything sold as replacing backups.

What a sensible owner should do this month

  • Two-factor login on email, accounting and every admin panel. Free with Google Workspace, Microsoft 365, Tally on cloud, Zoho and QuickBooks. Roughly two hours of an office manager's time. This single step blocks the most common path in.
  • List every account and kill the dead ones. Include the ex-accountant, the intern from last summer, the shared "admin" login your vendor set up in 2021.
  • Test a restore, do not just check that backups ran. Pick one file from three months ago and actually recover it. A small office pays roughly CAD 50 to 150 a month, or a few thousand rupees, for managed backup; an untested backup is worth nothing.
  • Make one payment rule: any change to a supplier's bank details is confirmed by voice call to a number you already had. Not the number in the email. This costs nothing and defeats the attack most likely to hit you.
  • Patch the boring boxes. The router, the CCTV recorder, the WordPress site, the old PC that runs one accounting program. These are what actually gets found.

If you do only one of these, do two-factor on email. If you want outside help, a one-off external check for a small business runs roughly ₹40,000 to ₹1,00,000 in India or CAD 1,500 to 4,000 in Canada, and is worth buying once, not subscribing to.

Also worth knowing

  1. EU rules requiring labels on realistic AI-generated content start today

    From August 2, the EU requires content that could pass for authentic to be labelled as AI-generated. If you sell into Europe, or run ads that reach European customers, this is now a compliance item rather than a preference. For everyone else it is a preview: labelling AI-made images and voiceovers in marketing is becoming the default expectation, and doing it before you are forced to costs you nothing.

    Hacker News ↗
  2. A researcher built a Word document that hijacks Microsoft Copilot and spreads itself

    A security researcher demonstrated a self-spreading worm hidden inside Word files that takes over Microsoft Copilot when the document is opened. This is a proof of concept, not something reported loose in the wild, but the principle matters: if your staff use Copilot on documents that arrive from outside, the document itself is untrusted input. Treat attachments from suppliers and job applicants with the same suspicion you already give links.

    the-decoder.com ↗
  3. DeepSeek's new cheap model puts more downward pressure on what AI work costs

    A detailed price and performance analysis of DeepSeek's V4 Flash release drew heavy attention among developers this week. You will not use it directly, but your software vendors do, and the direction of travel is cheaper. If you are being quoted a per-message or per-seat AI price on a multi-year contract, sign for one year, not three.

    Hacker News ↗
  4. A Copilot-in-Excel skeptic ran three real tests and changed their mind

    A hands-on write-up of three practical Excel tasks found Copilot genuinely useful where the writer expected it not to be. Excel is where most small businesses actually keep their operations, so this is closer to your daily reality than most AI news. Worth an hour from whoever maintains your stock, payroll or fee-collection sheets, before you pay anyone for a custom dashboard.

    How-To Geek ↗
  5. "AI doesn't generate working products, that's still your job"

    A widely read developer essay argues that AI produces plausible drafts, not finished systems, and that the hard work of making something actually run is unchanged. Read it before you accept a quote from an agency promising a full application in two weeks because "AI writes the code now." The saving in that pitch is real but modest, and it lands in the first draft, not in testing, deployment or the year of fixes afterwards.

    Hacker News ↗
  6. Chatbots give surprisingly decent financial answers, if you ask the right question

    A popular post makes the case that AI financial advice holds up well when the question is specific and poorly when it is vague. Useful for understanding your own options before a meeting with your CA or accountant; not a substitute for one, especially where Indian GST treatment or Canadian CRA rules turn on details the model was never told. Never paste client or patient financial records into a consumer chatbot to get the answer.

    Hacker News ↗
  7. Judge lets Minnesota's ban on "nudify" apps stand despite xAI's challenge

    A court declined to block a state ban on apps that generate fake nude images, rejecting xAI's request. The direct relevance to most businesses is small, but the signal is not: local governments are being allowed to restrict specific AI uses, and courts are not treating AI products as exempt. If you have not written a line into your staff handbook about generating images of colleagues or customers, this is the week to do it.

    TechCrunch AI ↗

How this briefing is put together

Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.

More editions

Published daily
A new edition every weekday morning, dated and kept permanently at its own address.
Every claim sourced
Each story links to the original announcement or report. Read them and disagree with us.
Written for owners
No benchmark scores or parameter counts — just what a development changes for a working business.

We use cookies

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. Learn more