Today's briefing
The price of attacking a small business just fell
A research group reports using Claude to break into OpenAI. For a 30-bed clinic or a 600-student school, the lesson is about cost, not science fiction.
The one that matters
Researchers say they used Claude to break into OpenAI — the real lesson is about cost
Dozens of outlets reported this week that a research group used Anthropic's Claude to break into systems belonging to OpenAI. The reporting is thin on the specifics that would matter most: who the group was, exactly what they reached, and how much the model did by itself versus being steered step by step by skilled people. Treat the details as unsettled. The part worth your attention is not the target, and not the brand of model. It is what the exercise implies about price.
What this actually changes for you
Breaking into an ordinary business has rarely been hard in a technical sense. It has been unprofitable. An attacker with real skill has always had better things to do than spend two days probing the fee portal of a 600-student school for a few thousand rupees of ransom. Most small businesses in India and Canada have been protected less by their firewalls than by that arithmetic.
Software that can grind through the boring parts — listing what you have exposed to the internet, trying known weaknesses against it, chaining together three small misconfigurations into one useful hole — pushes the hours per target down. When the hours fall, the attacker stops choosing targets and starts working through lists. The defence of "we are too small to be worth it" gets weaker every year, and this kind of demonstration is why.
Picture it concretely. A 600-student school with an online fee portal, one admin PC holding the student database, and parent groups on WhatsApp. A 30-bed clinic running patient records on a machine in reception and accounts in Tally. A workshop with 40 staff whose orders live in a cloud CRM that three supervisors log into with the same password. In every one of these, the way in is dull: an unpatched website plugin, a password reused between email and the accounting software, a vendor's remote-access tool installed in 2021 and never removed, one shared admin login.
What it does not mean
It does not mean a model can now rob a competent business on its own. What was reported is a research exercise run by capable people with a goal in mind, not a machine loose on the internet. It also does not mean you need to buy anything new. Over the next few weeks you will see pitches for "AI-powered threat monitoring" at roughly ₹15,000–40,000 a month, or CA$250–600, aimed at businesses with 40 staff. For a company your size that is usually an expensive answer to a problem you do not have, sold while the actual router firmware sits three years out of date. Insurance brokers and larger clients will also start asking sharper security questions in contracts — answer those honestly rather than buying a product to have something to point at.
What a sensible owner should do this month
- Turn on two-factor authentication on business email and on whichever system holds money or patient or student records. Free. One afternoon, plus a week of grumbling.
- Write down every outsider with remote access — the accounting firm, the website agency, the CCTV installer. Remove anyone you cannot name.
- Patch the things facing the internet: website plugins, the router or firewall, the CCTV recorder. These are the doors that get tried first.
- Test one restore from backup. Not that backups ran — that a file comes back. Half a day, and it is the single thing that decides whether ransomware is a bad week or the end of the business.
- Make one money rule: no bank-detail change and no urgent payment on the strength of an email or WhatsApp message alone. Call a number you already had.
Total cost: close to nothing except staff time. What changed this week is the price of an attacker's attention, not the invention of a new weapon. The work that protects you is the same boring work as last year — it just moved up the list.
Also worth knowing
-
Anthropic says Claude now handles about a quarter of its own AI research work
The 26% figure comes from the company itself, with no outside audit, so read it as a claim rather than a measurement. The practical consequence for you is pace: if model makers really are compressing their own development cycles, the tool your staff learned in March will behave differently by October. Write your processes around the task, not around one product's current menu.
CEO Today ↗ -
A US military close call traced to an intelligence report built on AI hallucination
The failure mode here is the dangerous one: a confident, well-formatted document containing facts that were never true. Exactly the same thing happens when a manager asks a chatbot to summarise a tender document, a lab result or a labour law clause. Set one rule — anything that triggers money, medicine or a legal commitment gets checked against the original source by a person before it moves.
Hacker News ↗ -
A zero-click flaw reported in Claude Code, Codex, Copilot and Gemini CLI plugins
Reported details are still limited, but the shape of it is a plugin-handling flaw in the AI coding tools your software vendor or in-house developer probably uses. If someone writes code for your business, ask two questions this week: have you updated these tools, and which third-party plugins are you running. It is a patching conversation, not a reason to ban the tools.
CyberSecurityNews ↗ -
Alibaba open-sources a medical model said to flag cancer and around 150 conditions
Freely downloadable weights are not an approved medical device, and no clinic in India or Canada can lean on this for diagnosis or billing without the relevant regulatory clearance. What it does signal is price pressure: imaging and screening software vendors will find it harder to justify per-scan fees when capable open models exist. If you are mid-way through a five-year contract for diagnostic software, that is worth remembering at renewal.
Hacker News ↗ -
AI-generated posters don't have to look terrible, if you direct them properly
A well-argued demonstration that the ugly results most people get come from lazy prompting and no design constraints, not from the tools being incapable. For a shop, restaurant or coaching centre spending ₹2,000–5,000 or CA$50–100 per poster on a freelancer, this is one of the few AI uses that pays for itself immediately. Keep a human check on spelling, prices and anything that counts as an advertised claim.
Hacker News ↗ -
A widely read argument that you should almost never use AI to write
The case is that writing is how you work out what you actually think, so outsourcing it quietly hollows out the thinking. A useful boundary for a business: let it draft the boilerplate — appointment reminders, tender checklists, routine job posts — and write the things that carry your judgement yourself. A fee-increase letter to parents or an apology to a customer you nearly lost is not a drafting problem.
Hacker News ↗ -
A Microsoft director calls AI training scrapes the largest theft of labour in history
Notable mainly because it comes from inside a company that benefits from the practice, which suggests the training-data fight has further to run in courts and contracts. If your business publishes anything — an agency, a publisher, a coaching institute with its own notes — expect licensing and permission clauses to start appearing in your agreements. Also worth checking what, if anything, your AI vendor indemnifies you for when its output resembles someone else's work.
Hacker News ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.