AI and IT News Recap: October 2, 2026: A 16-Year-Old Is Arrested as an Alleged Ransomware Boss, Half a Million Live Keys Sit on GitHub, and Google Unlocks a Guardrail-Free Gemini

By Noah Smith, Owner & Consultant, KeyChange Technologies · October 2, 2026

Pen-and-ink sketch of a long empty market street with uncovered stalls, where a teenage boy on a red bicycle tows a cart piled with crates toward two police officers waiting at the far end

A thinner news day than usual, but a few of these land close to home for any business with a website, a cloud account, or a contractor who writes code. Here is the AI and IT news worth your time for October 2, 2026.

📌 The AI and IT news at a glance

  • A 16-year-old is arrested as the alleged boss of a ransomware gang tied to about 1,000 attacks.
  • More than half a million passwords and API keys are still live on public GitHub, some of them for years.
  • A WordPress backdoor rebuilds itself every time you clean it out.
  • Google hands vetted security teams a version of Gemini 4 Argon with the cyber guardrails removed.
  • OpenAI says people tied to China's Moonshot AI tried to siphon off its models' reasoning.
  • Anthropic reportedly lines up a mid-November IPO at up to $2 trillion.
  • Claude Code gets "mods," and Claude Sonnet 4.5 gets a retirement date.

🔝 Top story: Police arrest a 16-year-old accused of running the KillSec ransomware gang

Spanish police arrested a 16-year-old in Alicante on suspicion of being the administrator of KillSec, a ransomware and extortion group that European investigators link to roughly 1,000 attacks over about two years. According to Reuters, two other suspects in their twenties were arrested in Britain and Romania, a fourth person who turned 18 in August has been identified, and police searched eight homes across Spain, Greece, Romania and Britain. Puerto Rico has filed an extradition request for the suspect held in Britain. The Hacker News reports police seized KillSec's leak site and servers, along with at least 110 terabytes of data, and that around 500 of the attacks are believed to have succeeded.

The detail that matters most for business owners is how KillSec got in. Europol said the group "exploited software vulnerabilities and poorly secured access points, particularly to cloud storage," then threatened to publish stolen data unless victims paid. In other words, this was not some nation-state superweapon. It was a teenager and a few associates finding storage buckets, file shares and logins that were left open or weakly protected, and doing it at scale. The operation involved Spanish, German, Romanian and U.S. authorities plus Europol and Eurojust.

In short: European police arrested a 16-year-old suspected of running KillSec, a group tied to roughly 1,000 ransomware and extortion attacks, mostly through poorly secured cloud storage.

What it means for your business: The barrier to entry for extortion is low, and the most common way in is still storage and logins nobody locked down. If you do not know who can reach your cloud storage from the internet, that is the question to answer this week.

My take: The age is the headline, but the method is the lesson. A kid did not need a zero-day to run a 1,000-victim operation; he needed people who left the door propped open. Most small businesses I talk to have at least one shared folder or cloud bucket set to "anyone with the link." Go find yours.

Source: The Hacker News: Police Arrest 16-Year-Old Suspected of Running KillSec


🛡️ IT and security

More than half a million live passwords and keys are sitting on public GitHub

Researchers at Truffle Security scanned public GitHub code and found more than 1.1 million exposed credentials, and when they re-tested them in July 2026, 543,699 still worked. The haul includes 69,041 Google Cloud service account credentials, 51,067 MongoDB database connection strings and 33,343 live Google API keys. The oldest working credential was an AWS key from 2009. The median secret had been sitting in public for 784 days, and about a quarter were more than four years old.

GitHub has turned on "push protection" by default, which blocks many secrets from being uploaded in the first place, but Truffle found 199,843 of the live credentials were pushed after that protection was switched on. Their core point: prevention does nothing for the secrets already out there. As Truffle put it, push protection "has nothing to say about the 543,699 already inside." What is missing, they argue, is automatic revocation, where a leaked key is killed the moment it is found.

In short: Truffle Security found 543,699 still-working passwords and API keys in public GitHub code, many exposed for years.

What it means for your business: If a developer, agency or freelancer has ever built something for you, there is a real chance one of your keys or database passwords is sitting in a public repository. Rotating keys on a schedule closes that window even if you never find the leak.

My take: This is my one technical pick today, and I picked it because it is not really technical. It is a hygiene problem with a dollar sign attached: a live cloud key can run up a bill or open a database. Ask whoever builds your software two questions: do we scan our code for secrets, and when did we last rotate our keys? If either answer is "um," you have your project for October.

Source: SecurityWeek: 500,000 Active Credentials Left Exposed on GitHub


A WordPress backdoor that rebuilds itself after you clean it up

Researchers at Sucuri, a website security company, detailed a WordPress backdoor they call SC that is built specifically to survive cleanup. It hides in at least eight places at once, spread across the site's files, its database and the server's shared memory, and each copy watches the others. Delete one and the rest put it back. Sucuri describes it as a circular system "with no single point you can remove to stop it."

Once in place, it creates hidden administrator accounts, hides itself from the admin screens, takes its instructions through the Ethereum blockchain so there is no single server to take down, can switch off or delete security plugins, and injects JavaScript that skims data from the site's visitors. Sucuri has not said how the sites were first infected or how many are affected; the usual entry points for this kind of malware are outdated plugins and themes, weak admin passwords, and compromised plugin updates.

In short: Sucuri found a WordPress backdoor that hides in eight places and reinstalls itself when any one copy is removed, then skims site visitors.

What it means for your business: If your website runs on WordPress, a "we removed the malware" fix may not be a fix. Infected sites need a full rebuild from known-clean backups, new admin passwords, and a check for admin accounts you did not create.

My take: WordPress powers a huge share of small business websites, which is why this one made the cut. The practical move today costs nothing: log in, look at your list of admin users, and delete anyone you do not recognize. Then make sure plugins update automatically and that someone actually owns the site, not just "the guy who built it in 2021."

Source: The Hacker News: WordPress Backdoor Rebuilds Itself After Cleanup


🤖 AI

Google gives vetted defenders a Gemini 4 Argon with the cyber guardrails off

Google's new flagship model, Gemini 4 Argon, which we covered in yesterday's AI and IT news recap, is now rolling out to security teams through Google's Fairwind Program, a limited-access effort for governments, Google Cloud customers and security partners that started in September with more than 650 organizations. The bigger news is the access model: for trusted defenders and Google's own teams, Google is releasing Argon "without cyber guardrails" so it can find, confirm and patch vulnerabilities on its own.

Google says Argon uncovered a critical flaw exposing sensitive personal information in healthcare software used by hospitals worldwide, one that earlier models missed, though it has not named the software or said whether it is fixed. Before any wider release, Google says it has added misuse monitoring, stronger defenses against prompt injection, and checks that watch the model's reasoning and halt it when needed.

In short: Google is giving vetted security teams an unrestricted version of Gemini 4 Argon for finding and fixing software flaws.

What it means for your business: The vendors you rely on will be finding and patching bugs faster, which also means more patches landing on your desk, faster. A slow patch routine gets more expensive every month.

My take: OpenAI, Anthropic and now Google are all handing their sharpest tools to defenders first. That is the right order, but it is still a race, and the same capability will reach attackers eventually. Treat "patch within days, not quarters" as the new normal.

Source: SecurityWeek: Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders


OpenAI says Moonshot AI associates tried to extract its models' hidden reasoning

OpenAI disclosed that it shut down a coordinated campaign to pull protected reasoning out of its models, and it attributed "a core cluster of the activity" to people associated with Moonshot AI, the Beijing company behind the Kimi chatbot. The campaign started at low volume in early July, spiked on July 24 and 25 to about 16,000 attempted requests from more than 4,000 users, and was fully disrupted by July 28. OpenAI says the operators did not break its encryption or touch stored user conversations; they abused normal model interactions to try to reproduce reasoning the company keeps hidden.

OpenAI acknowledged it is not certain every operator came from one source and offered no evidence that Moonshot's models were actually trained on what was taken. Moonshot had not responded publicly in the coverage we reviewed. The disclosure follows Anthropic's September report accusing several Chinese labs, including Moonshot, of similar "distillation" campaigns against Claude.

In short: OpenAI says it stopped a July campaign, which it ties to people associated with Moonshot AI, to copy its models' hidden reasoning.

What it means for your business: Copying a frontier model's reasoning lets a competitor skip both the cost and the safety work. If you are choosing cheap AI models from lesser-known providers, ask how they were built and what safeguards came along.

My take: This is mostly a fight between AI giants, but it shapes your options. Bargain models are not automatically bad, and these are still allegations, but "where did this model come from" is now a fair procurement question.

Source: The Hacker News: OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates


Anthropic reportedly targets a mid-November IPO at up to $2 trillion

Bloomberg reports that Anthropic is aiming to go public as soon as mid-November, later than the October debut many investors expected. According to that reporting, as summarized by Yahoo Finance, the company is set to meet prospective investors on October 14 and could begin formally marketing the offering the week of November 9, at a valuation of up to $2 trillion, which would make it the largest IPO ever. Anthropic has not publicly confirmed the timetable.

In short: Anthropic is reportedly planning an IPO as soon as mid-November at a valuation of up to $2 trillion.

What it means for your business: A public Anthropic will face quarterly pressure on pricing and growth. If Claude is part of your workflow, expect more product launches and more attention on how plans are priced.

My take: Nothing changes for Claude customers this week. Over the next year, public-market pressure tends to push prices and plan terms around, so keep your AI usage portable enough that you are not stuck if terms shift.

Source: Yahoo Finance: Anthropic reportedly looking to IPO as early as mid-November


🧰 Tools for builders and business AI

Claude Code gets mods, small add-ons that change how it works

Anthropic launched mods for Claude Code, its AI coding assistant: small TypeScript functions that can rewrite a prompt before it reaches the model, block or change actions the agent tries to take, handle permission requests, redact sensitive information from output, and add or replace parts of the interface. Mods run in the Claude Code command line and desktop app, ship inside plugins from the Claude directory, and can be stacked. You can also ask Claude Code to write one for you. Team and Enterprise plans get a built-in security mod, sec-default, that loads first.

The catch is spelled out by Anthropic itself: mods are not sandboxed. They run with the same access to your machine as Claude Code, so "you should only install mods from sources you trust, the same way you'd install any code."

In short: Anthropic added mods to Claude Code, letting teams customize its prompts, permissions and interface with small code add-ons.

What it means for your business: If your team uses Claude Code, mods are a way to enforce your own rules, like redacting customer data or blocking risky commands. They are also a new kind of software to vet before anyone installs it.

My take: For a team, the useful mods will be the boring ones: block deploys on Friday, scrub secrets from logs, require approval before touching production. Put a rule in place now that nobody installs a third-party mod without a second set of eyes.

Source: Claude blog: Customize Claude Code with mods in TypeScript


Claude Sonnet 4.5 retires November 30

Anthropic notified developers on September 30 that Claude Sonnet 4.5 (model ID claude-sonnet-4-5-20250929) is deprecated and will be retired from the Claude API on November 30, 2026. After that date, requests to that model will fail. Anthropic recommends moving to Claude Sonnet 5.5.

In short: Claude Sonnet 4.5 stops working on the Claude API on November 30, 2026.

What it means for your business: If any tool, chatbot or automation you paid someone to build calls Sonnet 4.5 directly, it will break in about two months unless someone updates it.

My take: Model retirements are the "your SSL certificate expired" of the AI era. Ask your developer or vendor today which model IDs your tools use, and put November 30 on the calendar with a test date two weeks earlier.

Source: Claude Docs: Model deprecations


That is the AI and IT news for today. If one of these touches your setup and you are not sure where to start, start with the free checks: your cloud sharing settings, your WordPress admin list, and which AI model your tools call.