Workaholic Developers

No. 38

Today's briefing

The attackers got cheaper before your defences did

Anthropic's fourth disclosed misuse case says less about clever machines than about how cheap ordinary attacks have become, and how late anyone notices.

8 stories Sourced from Yahoo! Finance Canada, OpenAI, Digital Watch Observatory, GV Wire and others
Abstract illustration accompanying The attackers got cheaper before your defences did
Abstract illustration, generated with AI. It represents the idea, not the event.

The one that matters

Anthropic found a fourth case of its AI used in an attack — its own earlier review had missed it

Yahoo! Finance Canada ↗

Anthropic has disclosed a fourth cybersecurity incident involving an early version of its Claude model. The number is not the interesting part. The interesting part is that this one was found late: an earlier internal review covered the same ground and did not catch it. The company went back, found it, and said so.

That is genuinely all the public reporting supports. It does not say who was attacked, in which country, what was taken, or what it cost anyone. If you read a write-up that fills in those blanks, the write-up is guessing.

What this actually means for your business

It does not mean a machine is hunting your servers. It means the labour cost of an ordinary attack keeps falling. The attacks that hurt a 600-student school or a 30-bed clinic have never been clever. They are a fake fee-payment notice to 400 parents. They are an email that looks like it came from the principal asking accounts to release a payment before Friday. They are a supplier invoice at a 40-person workshop, correct in every detail except the bank account number at the bottom.

Those attacks used to need a person who could write clean English or clean Hindi, research your staff list, and keep track of replies. That person was the bottleneck. Software that drafts, researches and replies removes the bottleneck. So expect the same attacks, better spelled, referencing your actual vendor names, arriving in larger volume. Nothing about the defence changes. The odds of you being tried at all go up.

What it does not mean, and who is overstating it

Two groups are inflating this in opposite directions. Security vendors will use it to sell "AI-powered threat detection" to businesses that have not yet turned on two-factor authentication — that is selling a lock for the roof while the front door is open. On the other side, commentators will present this as proof that these systems are already beyond anyone's control. A missed-then-found review does not show that. It shows the ordinary thing: monitoring at these companies is imperfect and disclosure lags reality.

The useful takeaway is narrower and more durable. Every AI vendor's safety assurance is a claim about what they have detected so far, not a guarantee about what happened. Treat it the way you would treat a supplier's own quality report.

What a sensible owner should do this month

  • Turn on two-factor authentication for every email account, starting with accounts, admin and the owner. It is already included in Google Workspace and Microsoft 365. Cost: one afternoon of your IT person's time.
  • Write down one rule about bank details: any request to change a supplier's or employee's account number is verified by phone, on a number you already had on file, never the number in the message. Free. This single rule prevents the most expensive thing that happens to firms your size.
  • Test a restore, not a backup. Pick one file from last month and actually recover it. A morning of your own time, or roughly ₹10,000–₹20,000 / CAD $200–$400 for a contractor's day.
  • Close the accounts of people who left and kill shared logins where three staff use one password.
  • Put half a page on the wall: who to call, in what order, if money moves wrongly or systems lock up.

None of that is about AI. That is the point. The threat got cheaper to produce; the defence did not change, and most businesses still have not done it.

Also worth knowing

  1. OpenAI launches GPT-6 Astra, pitched at business work and operating software directly

    OpenAI says its new model is its most capable for business, with stronger reasoning and "computer use" — meaning it clicks through existing applications rather than just writing text. This is a launch post, not an independent test, so treat every claim as unverified for now. If it holds up, the first real uses are dull and valuable: reconciling statements, filling forms, moving data between systems nobody wants to integrate. Do not restructure a team around it this month.

    OpenAI ↗
  2. Class action filed over how Anthropic described Claude usage limits

    A user has sued Anthropic over its usage-limit claims. Whatever the legal merits, the operational lesson is free: plans that feel unlimited in a demo throttle under real load. Before you standardise 20 staff on any one AI subscription, run it for two weeks at your busiest volume and keep a second vendor's account open.

    Digital Watch Observatory ↗
  3. Microsoft Copilot goes down for thousands of users

    Downdetector logged a large spike of Copilot outage reports. If your team drafts quotes, case notes or client emails inside a tool like this, an outage is not an inconvenience, it is a work stoppage with no warning and no escalation path you control. Decide now what people do for the two hours it is dark, and make sure the answer is written somewhere other than in the tool.

    GV Wire ↗
  4. IBM releases a time-series forecasting model under a commercial-friendly licence

    IBM has put out a new Granite time-series model with a licence that permits commercial use, aimed at forecasting from historical numbers — footfall, demand, load. For a distributor or a factory this is closer to genuinely useful than most model news, because stock and staffing forecasts are real money. But it is a model release, not a product: you need a developer, and you need 18 to 24 months of clean sales history before anyone can build anything worth trusting.

    Hugging Face ↗
  5. A claimed AI mathematics breakthrough turns into a dispute over what was proved

    An AI-produced mathematical result has drawn public argument among researchers about what was actually established. You do not need the mathematics; you need the pattern. If specialists need weeks to agree whether a claim in their own field is real, then a vendor telling your clinic that "our AI handles scheduling" earns a two-week paid pilot, not a purchase order.

    Hacker News ↗
  6. Anthropic researcher resigns, warning publicly against self-improving AI

    A researcher left Anthropic and went public with a warning about systems that improve themselves, saying the industry is taking an unacceptable risk. This changes nothing about your quarter and there is no action for you here. It is worth one minute of attention only as evidence that people inside these companies disagree sharply about their own products, which is a reason to read safety marketing as marketing.

    TechCrunch ↗
  7. A PCMag comparison argues Apple's new macOS overtook Microsoft's AI lead

    One review argues that Apple's latest macOS release has caught and passed Microsoft's three-year head start on built-in AI features. That is one publication's opinion about desktop software, not a business finding. It matters only if you are already replacing laptops this cycle, in which case it is a question to ask your supplier; it is never a reason to switch platforms and retrain staff.

    PCMag UK ↗

How this briefing is put together

Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.

More editions

Published daily
A new edition every weekday morning, dated and kept permanently at its own address.
Every claim sourced
Each story links to the original announcement or report. Read them and disagree with us.
Written for owners
No benchmark scores or parameter counts — just what a development changes for a working business.

We use cookies

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. Learn more