AI and IT News Recap: August 28, 2026: Anthropic Teaches Claude to Run the Lab, a Ransomware Affiliate Runs on Cursor AI, and Manchester Airports Loses 8.7 Million Records

By Noah Smith, Owner & Consultant, KeyChange Technologies ยท August 30, 2026

Hand-drawn pen-and-ink illustration of a hand holding a conductor's baton leading a semicircle of laboratory machines, a microscope, a robotic arm, a liquid handler, and a centrifuge, at night while a researcher sleeps at a desk, a metaphor for AI operating lab and factory hardware.

Your fast, no-spin read on the AI and IT news that actually matters to a business owner today.

๐Ÿ“Œ The AI and IT news at a glance

  • ๐Ÿ” Anthropic previewed the Model Hardware Standard (MHS), a way to let Claude and other models safely operate lab and factory machines.
  • ๐Ÿค– Anthropic opened 10,000 free and discounted Claude seats for scientists and widened its AI for Science credits.
  • ๐Ÿ›ก๏ธ Manchester Airports Group lost data on about 8.7 million customers, much of it collected through airport Wi-Fi sign-ups.
  • ๐Ÿ›ก๏ธ An Aurora ransomware affiliate ran the Cursor AI coding assistant to help plan intrusions at more than 20 organizations.
  • ๐Ÿ›ก๏ธ Australian police charged two alleged TeamPCP hackers tied to supply-chain attacks that touched more than 1,000 organizations.
  • ๐Ÿ›ก๏ธ A prompt-injection flaw in Amazon's Kiro AI IDE could quietly siphon secrets out of a developer's workspace.
  • ๐Ÿงฐ GitHub Copilot CLI shipped v1.0.81 with a plugins dashboard for skills, MCP servers, and extensions.

Missed yesterday? Catch up with the August 27 recap.


๐Ÿ” Top story: Anthropic gives Claude a way to run real-world machines

Anthropic opened a research preview of the Model Hardware Standard, or MHS, a shared specification that lets AI agents operate physical instruments such as microscopes, liquid handlers, and robotic arms. Instead of a specialist spending weeks writing a custom integration, a hardware vendor can describe in an MHS file how a machine works and how it must be operated safely, for example capping the speed or angle of a heavy robotic arm. Anthropic says that drops the time to connect an AI to a piece of equipment from weeks or months down to hours or minutes, and that agents can run instruments around the clock and, in some cases, recover from hardware errors on their own.

The standard is model-agnostic, so it is meant to work with any large language model, not only Claude, and Anthropic plans to open source it after building out safety evaluations with partners. Early collaborators named at launch include Genentech, Carnegie Mellon, HHMI Janelia, the University of Washington, AWS, lab-automation vendor Tecan, Universal Robots, Hugging Face's LeRobot project, QIAGEN, and Raspberry Pi. This is Anthropic's first real move out of the browser and into the physical world, and it lands as the EU's updated machinery rules that govern AI-driven equipment come into focus for 2027.

In short: Anthropic released a research-preview standard that lets AI agents safely drive lab and factory hardware, and it plans to open source it.

What it means for your business: If your company runs any kind of physical process, from a lab bench to a warehouse, this is the early groundwork for AI that touches equipment rather than just documents. It is a preview, not a product, so the practical move now is to note which of your vendors are on the partner list and to start thinking about who signs off on an agent that can move a machine.

My take: Software mistakes get rolled back. A robotic arm moving at the wrong angle does not. The most interesting part of MHS is not that Claude can run a microscope, it is that the safety limits live in the hardware description itself. That is the right instinct, and it is worth watching whether the open-source version keeps those guardrails mandatory or optional. For now this is a research preview, so treat the demos as direction, not capability you can buy tomorrow.

Source: Previewing the Model Hardware Standard, Anthropic


๐Ÿค– AI

Anthropic opens 10,000 Claude seats for scientists

On the same day, Anthropic said it is giving away and discounting 10,000 Claude Team seats for scientists. Under the new Claude Team plan for scientists, standard seats are free and premium seats with five times the usage limits run

5 a month, with pricing locked for a year. To qualify, a principal investigator at an academic or nonprofit research institution completes a verification form and can then add the researchers in their lab. Anthropic also widened its AI for Science program, which hands out compute credits worth up to $50,000 for qualifying projects, and expanded it beyond biology into other compute-heavy fields.

In short: Anthropic is offering 10,000 free and discounted Claude seats to verified academic and nonprofit researchers, plus larger AI for Science compute grants.

What it means for your business: If you partner with universities, run an R&D group, or hire out of research labs, expect the people you work with to show up already fluent in Claude. Cheap, verified access to a frontier model inside academia tends to set the default tools graduates carry into industry.

My take: This is a smart, low-cost land grab. Seed a generation of researchers on your model and you shape which assistant they reach for a decade from now. The verification gate keeps it honest, and the science framing is genuinely useful, but do not mistake generosity for charity. It is distribution strategy, and a good one.

Source: Anthropic Opens 10,000 Free and Discounted Claude Seats for Scientists, Unite.AI


๐Ÿ›ก๏ธ IT and security

Manchester Airports Group loses data on 8.7 million customers

Manchester Airports Group, which runs Manchester, Stansted, and East Midlands airports, confirmed that attackers stole customer data on roughly 8.7 million people. Much of it came from airport Wi-Fi registrations along with bookings for parking, lounges, and Fast Track services. Exposed fields can include email addresses, phone numbers, postal codes, and vehicle registration numbers. MAG says no bank or payment details were held in the affected system, that it contained the incident quickly, and that flights and aviation security were never affected. The bigger risk now is phishing, because attackers hold exactly the contact and travel details that make a fake airport or parking message look real.

In short: A breach at Manchester Airports Group exposed contact and booking data for about 8.7 million travelers, though no payment data was taken.

What it means for your business: Data you collect for a small convenience, like a Wi-Fi sign-up, is still a breach liability years later. If your business gathers customer contact details through a free portal or a loyalty perk, that database carries the same duty of care as your billing system, and the same phishing exposure if it leaks.

My take: The lesson here is not airport security, it is data hoarding. A Wi-Fi splash page does not need someone's vehicle registration for a year. Every field you keep is a field an attacker can steal, so collect less and delete sooner. If your customers passed through those airports, brief them that a convincing parking or booking scam is now likely.

Source: Manchester Airports Group says hackers stole travelers' data, BleepingComputer

An Aurora ransomware affiliate ran on Cursor AI

Researchers at CloudSEK got a rare inside look at a ransomware operator after the affiliate left a server exposed. The logs show a Russian-speaking affiliate of the Aurora ransomware operation using the AI coding assistant Cursor to plan intrusions and Active Directory privilege escalation across more than 20 organizations in nine countries between April and July 2026. The operator reached domain-level or interactive access at 17 targets, and four victims ended up on Aurora's public leak site. The exposed server held the affiliate's tools, command history, stolen credentials, Aurora encryptor, and the actual Cursor chat records, with the operator's notes and AI planning sessions written in Russian. Manufacturing, food, agriculture, and professional services firms were among those hit.

In short: A misconfigured server revealed an Aurora ransomware affiliate using Cursor's AI assistant to plan attacks on 20-plus organizations across nine countries.

What it means for your business: The same AI tools that speed up your developers speed up the people attacking you. Attackers now move faster from a foothold to full domain control, which shrinks the window you have to detect and respond. Mid-size companies in manufacturing and food and agriculture were squarely in scope, so this is not a big-enterprise-only problem.

My take: Do not read this as "AI writes malware," because that is not what happened. The attacker used a normal coding assistant as a force multiplier for ordinary intrusion work, which is both more mundane and more concerning. Your defenses do not need an AI angle to counter it. Fast detection, tight Active Directory hygiene, and least-privilege access still do the job. The clock just runs faster now.

Source: Caught in 4K: The Aurora Files, CloudSEK

Australia charges two alleged TeamPCP hackers

The Australian Federal Police charged two Western Australian men, aged 23 and 21, with a combined 14 offences over their alleged role in TeamPCP, the group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Police say the malicious code potentially reached more than 1,000 organizations worldwide, enabled the theft of more than 500,000 credentials, and led to at least 300 gigabytes of exfiltrated data. Investigators, aided by research from threat-intel firm KELA, executed search warrants and seized devices before the pair appeared in a Perth court. The two allegedly took payment in cryptocurrency, the value of which is still being worked out.

In short: Australian police charged two men over the TeamPCP supply-chain attacks that hit developer security tools and reached more than 1,000 organizations.

What it means for your business: This is a reminder that a single poisoned developer tool can quietly reach a thousand downstream companies, and yours could be one without ever being a direct target. If your teams use open-source scanners or AI gateways, know which versions you run and whether you were exposed during the March 2026 window.

My take: Two arrests are a real win, and it is good to see supply-chain attackers actually face charges rather than vanish. But the damage was done months ago, and the tools involved were security tools, the ones meant to protect you. Trust in your toolchain has to be verified, not assumed. Pin your versions, watch for tampering, and do not treat "it is a security product" as a reason to trust it blindly.

Source: Australia arrests alleged TeamPCP hackers behind supply-chain attacks, BleepingComputer

A prompt-injection flaw in Amazon's Kiro AI IDE

Researchers disclosed a prompt-injection weakness in Amazon Kiro, an AI-powered agentic coding environment, that could exfiltrate sensitive data without the developer ever asking for it. An attacker plants crafted content in a repository, and once a developer opens that workspace and sends any message to the agent, the injected instructions run. In the demonstrated chain, the agent reads a local .env file, uses grep to find API keys while dodging simple filters, tucks the stolen key into a URL, and calls Kiro's built-in URL-fetch feature to ship the data to an attacker. The flaw, which does not carry a CVE, was reported responsibly and has been patched, so the fix is to update to the latest version.

In short: A now-patched prompt-injection flaw let Amazon's Kiro AI IDE leak workspace secrets like API keys just from opening a booby-trapped repo.

What it means for your business: Agentic coding tools read everything in a project folder, including the secrets your developers keep there. Cloning an untrusted repo into an AI IDE is now a real exposure, not a theoretical one. Update Kiro, and make sure secrets live in a vault rather than a plaintext .env file sitting in the workspace.

My take: This is the defining security problem of agentic AI in one example. The tool did exactly what it was told, the instructions just came from a file instead of the user. Keeping humans in the loop for actions like fetching a URL or reading credentials is not friction, it is the control. Patch Kiro, but also assume the next agent you adopt has a version of this same hole.

Source: Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers, The Hacker News


๐Ÿงฐ New tooling for builders and business

GitHub Copilot CLI v1.0.81 adds a plugins dashboard

GitHub shipped version 1.0.81 of its Copilot CLI, the terminal version of Copilot. The headline is a new plugins dashboard, reachable by running /plugin, /mcp, or /skills, that gives you one place to manage extensions, connected MCP servers, and skills. The release also adds support for the newer MCP 2026-07-28 spec across the CLI, SDK, IDE, and in-memory clients, wires OpenTelemetry trace context into hooks, and lets Windows users sign in to remote MCP servers protected by Microsoft Entra ID through the operating system's authentication broker. You can opt out of the dashboard with an environment variable if you prefer the older flow.

In short: GitHub Copilot CLI v1.0.81 adds a plugins dashboard for skills, MCP servers, and extensions, plus newer MCP support and Entra ID sign-in on Windows.

What it means for your business: If your developers work in the terminal, managing Copilot's extensions and connected tools just got easier, and the Entra ID support makes it friendlier for locked-down corporate environments. It is a small release, but the direction, treating skills and MCP servers as first-class managed pieces, is where the tooling is heading.

My take: The interesting signal here is not the dashboard, it is that MCP and skills are becoming standard plumbing you are expected to manage, not experiments. If you are letting developers connect Copilot to internal MCP servers, decide now who approves those connections. A convenient dashboard also makes it convenient to attach something you should not.

Source: GitHub Copilot CLI v1.0.81 release notes, GitHub


That is the AI and IT news that matters for August 28, 2026. Have a question about how any of this hits your business? Reach out to the KeyChange team, and check back tomorrow for the next recap.