AI and IT News Recap: June 24, 2026: Five Eyes Warns AI Cyberattacks Are Months Away, Oracle Cuts 21,000 Jobs, and a CISA Patch Deadline Lands
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท June 24, 2026

A lighter day on the AI and IT news beat, but the stories that did land share a theme worth sitting with: the same AI driving the gold rush is now reshaping who attacks you, who works for you, and what you have to patch this week. Here is the AI and IT news that actually affects how you run your business today.
๐ The AI and IT news at a glance
- ๐ The Five Eyes intelligence alliance warned that AI capable of crippling cyberattacks is "months, not years" away and told organizations to "act now."
- ๐ค Oracle confirmed it shed about 21,000 jobs over the past year, tying the cuts directly to its AI buildout.
- ๐ก๏ธ A CISA federal patch deadline landed today for three actively exploited flaws in Chrome, Cisco, and Arista gear.
๐ Top story: Five Eyes says AI cyberattacks are "months, not years" away
The intelligence agencies of the Five Eyes alliance (the United States, United Kingdom, Australia, Canada, and New Zealand) issued a joint warning that frontier AI models are close to being able to plan and execute cyberattacks powerful enough to overwhelm the defenses of governments and major companies. Their framing was blunt: this capability is "months, not years" away, and the agencies urged organizations to "act now" rather than treat it as a future problem. The statement said frontier models are expected to exceed current industry expectations and to fundamentally transform both offensive and defensive cyber capabilities.
What makes this notable is who is saying it. This is not a vendor selling a product or a think tank floating a scenario; it is the combined signals-intelligence establishment of five governments putting a public clock on a threat they normally describe in vague terms. The practical worry is that AI lowers the skill floor for sophisticated attacks, letting less capable actors chain together reconnaissance, exploitation, and lateral movement at machine speed.
In short: A Five Eyes joint statement warned that AI models capable of launching crippling cyberattacks are only months away and urged governments and businesses to strengthen defenses now.
What it means for your business: You do not need a nation-state budget to be a target when attacks get cheaper and faster to run. The fundamentals still buy you the most protection: multi-factor authentication everywhere, fast patching, tested backups, and an incident plan you have actually rehearsed. The window the agencies are describing is short enough that "we will get to it" is the risky answer.
My take: Government cyber warnings usually age into background noise, so the specific "months, not years" language is worth respecting precisely because these agencies hate committing to timelines. I would not panic-buy an AI security product off the back of it. The unglamorous basics are still what stops the overwhelming majority of attacks, AI-assisted or not, and the smartest response is to close the gaps you already know about before something automated finds them for you.
Source: Euronews: AI cyber threat is 'months, not years' away, Western intelligence agencies warn
๐ค Oracle cut about 21,000 jobs and pointed at AI
Oracle disclosed in its annual regulatory filing that it reduced its workforce by roughly 21,000 roles, close to 13 percent, over the past year, bringing its full-time headcount to about 141,000 as of May 2026, down from around 162,000 a year earlier. The company explicitly connected the cuts to AI, stating that the adoption and deployment of AI technologies across its operations have resulted, and may continue to result, in workforce reductions. Oracle spent about
The pattern is becoming familiar across big tech: spend enormous sums building AI data centers while trimming the human workforce and crediting AI for the efficiency. Whether AI is the true cause or a convenient explanation for cost discipline under investor pressure is a fair debate, but the headline is the same to anyone watching the labor market.
In short: Oracle confirmed roughly 21,000 job cuts over the past year and tied them directly to its AI adoption, even as AI infrastructure spending surged.
What it means for your business: When a company the size of Oracle frames layoffs as an AI efficiency story, expect that narrative to shape vendor pitches, customer expectations, and your own team's anxieties. The useful takeaway is not to cut headcount because Oracle did; it is to ask honestly where AI genuinely removes drudgery in your operations versus where "AI savings" is just a cover for doing less.
My take: I read these announcements with some skepticism. "AI made us do it" is an easy story to tell investors when you are also taking on heavy debt for data centers and need to show discipline somewhere. AI is clearly automating real work, but it is also becoming the all-purpose justification for cuts that would have happened anyway. For a small or mid-size business, the lesson is to measure AI's impact on your own workflows directly rather than assuming the giants' math applies to you.
Source: CNBC: Oracle sheds 21,000 roles over the past year amid wave of AI layoffs from tech giants
๐ก๏ธ A CISA patch deadline landed today for three exploited flaws
Today marked the federal remediation deadline for three actively exploited vulnerabilities that CISA added to its Known Exploited Vulnerabilities catalog. The most broadly relevant is a Google Chrome V8 zero-day (CVE-2026-11645, CVSS 8.8), an out-of-bounds read-and-write flaw that lets a remote attacker run code via a crafted web page. The other two hit network infrastructure: a Cisco Catalyst SD-WAN Manager flaw (CVE-2026-20245, CVSS 7.8) that allows an authenticated local attacker to execute commands as root, and an Arista EOS flaw (CVE-2026-7473, CVSS 6.9) that lets unexpected tunneled traffic be processed without authentication. Federal civilian agencies were ordered to fix or mitigate all three by today, June 23.
The Arista entry has an unusual wrinkle: the company says it is not planning a patch, because a fix could break existing customer configurations. Instead it recommends mitigating with access control lists on upstream devices or on the affected switches. The Chrome bug is the one nearly every business should care about, because it is exploited in the wild and a browser update closes it.
In short: A CISA deadline arrived today for three exploited flaws, including an in-the-wild Chrome V8 zero-day and flaws in Cisco and Arista network gear, with Arista opting for mitigations instead of a patch.
What it means for your business: Federal deadlines are not binding on private companies, but the KEV catalog is a clean priority list of bugs attackers are actually using. Make sure Chrome is fully updated and restarted across your fleet, since that one affects everybody, and if you run Cisco SD-WAN or Arista switches, treat their advisories as urgent rather than routine.
My take: The Chrome zero-day is the practical action item here; everything else is for the networking team. What stands out is Arista declining to patch and pushing mitigations instead. That is a defensible engineering call given the breakage risk, but it quietly shifts the work onto customers, who now have to get access-control rules right rather than just installing an update. "There is no patch, here are some configs" is a meaningfully harder ask, and worth flagging to whoever owns your network.
Source: The Hacker News: CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Catch up on yesterday's stories in our June 23, 2026 AI and IT News Recap.