AI and IT News Recap: October 8, 2026: The FBI Says FortiBleed Is Still Locking Firms Out of Their Own Firewalls, Four States Sue TP-Link, and Claude Haiku 5.5 Undercuts Its Predecessor by Up to 90%
By Noah Smith, Owner & Consultant, KeyChange Technologies · October 8, 2026

Here is today's AI and IT news for busy owners: the FBI says a firewall break-in campaign is still locking businesses out of their own networks, four states take TP-Link to court, and Anthropic ships a small Claude model for up to 90% less than its predecessor.
📌 The AI and IT news at a glance
- FBI: FortiBleed attacks are still running, with stolen logins for 86,644 Fortinet firewalls feeding ransomware crews.
- Hackers hijacked three countries' domain registries and got real security certificates for Google web addresses.
- Four states sue TP-Link, saying it hid its China ties and oversold its routers' security.
- A ransomware "recovery" CEO is charged with fraud for quietly paying the hackers and billing victims far more.
- Outlook will block Windows app installer attachments starting in November.
- Chrome 155 fixes 247 security flaws, many of them found with AI.
- The Dutch tax office drops Microsoft 365's cloud and moves its email back in-house.
- Anthropic launches Claude Haiku 5.5 at up to 90% less than its predecessor.
- ChatGPT gets "Intelligent UI": clickable charts, calculators and maps inside answers.
- Common Sense Media calls ChatGPT for Teens an "unacceptable risk."
- Microsoft's Copilot learns to mix local and cloud AI and search your files on request.
- AWS open-sources Strands Box, a sandbox that keeps AI agents on a leash.
🔝 Top story: The FBI says the FortiBleed firewall attacks are still locking businesses out
The FBI and the Secret Service warned this week that the FortiBleed campaign against Fortinet FortiGate firewalls and SSL VPN gateways is still active. FortiGate boxes sit at the front door of a huge number of small and mid-sized business networks, and this campaign has been harvesting the logins for them since at least June, when an exposed server turned up usernames and plaintext passwords tied to roughly 74,000 firewall addresses in 194 countries. Security firm SOCRadar now counts 86,644 compromised devices.
The attackers get in with leaked or reused passwords, infostealer logs and password spraying, then pull more credential data off the device and crack it offline on a rack of graphics cards. In some cases they create their own admin accounts, delete or change the passwords of the real admins, and lock the owner out of their own firewall before moving deeper into the network. The FBI says this access has been used as an entry point by ransomware affiliates, naming the INC and Lynx operations, and its guidance is blunt: patching and a password change alone may not be enough.
In short: The FBI says stolen Fortinet firewall logins are still being used to break into networks and hand access to ransomware gangs.
What it means for your business: If your office runs a FortiGate firewall or VPN, assume it needs a check, not just an update: kill active VPN sessions, reset every admin and VPN password, turn on MFA, and confirm no new admin accounts have appeared.
My take: This is the nightmare version of "set it and forget it." The firewall is the one box nobody looks at until the internet stops working, and that is exactly why it makes such a good hiding spot. If your IT provider set yours up years ago, ask them this week when someone last logged in to it, and from where. If nobody can answer, that is your answer.
Source: BleepingComputer: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
🛡️ IT and security
Hackers hijacked three national domain registries and got real certificates for Google addresses
Attackers broke into third-party operators that run the internet domain registries for Ghana (.gh), Sierra Leone (.sl) and American Samoa (.as), then changed the master address records for domains under those country endings. With that control, they could prove "ownership" of those domains to certificate authorities and walk away with valid HTTPS certificates, the same padlock-icon certificates your browser trusts. Several Google domains were hit, and certificate logs later showed other organizations, including what BleepingComputer describes as several leading global brands and widely used online services.
Google says its own systems were not compromised. It blocked the rogue certificates in Chrome, worked with the issuing authorities to revoke them, and notified affected organizations it could find, but it warned it may not have caught every domain and that its Chrome block does not protect people using other browsers. The attackers have not been identified.
In short: Attackers hijacked three countries' domain registries and obtained valid security certificates for Google and other brands' web addresses.
What it means for your business: The padlock in the address bar proves a site has a certificate, not that the right people are behind it, so any domain your company owns, including parked ones, is worth watching.
My take: This is my one technical pick today, and it earns the slot because it breaks an assumption almost everyone holds: that a valid certificate means a real site. The practical step is cheap. Ask whoever manages your domains to set up certificate monitoring and add a CAA record, which tells the world which certificate companies are allowed to issue for you.
Source: BleepingComputer: Hackers hijack Google domains after breaching ccTLD registries
Four states sue TP-Link over its China ties and router security claims
The attorneys general of Florida, Iowa, Montana and Nebraska have sued TP-Link Systems, the California-based company behind one of the best-selling home and small-office router brands in the U.S. The states allege TP-Link hid "past and ongoing ties to the People's Republic of China," that its supply chain leans heavily on Chinese companies, and that its devices have had repeated firmware vulnerabilities. They also point to marketing such as the claim that its HomeShield feature "covers all security scenarios," which they call misleading.
TP-Link calls the allegations baseless, says it is a U.S. company whose U.S. products are made in Vietnam, and says it looks forward to refuting the claims in court. Texas filed a similar suit earlier this year. These are allegations in a lawsuit, not findings.
In short: Four states sued TP-Link, alleging it misled buyers about its China ties and the security of its routers.
What it means for your business: If a TP-Link router or mesh system is running your office or your remote staff's home connections, this is a good moment to confirm firmware is current and to note it as a possible replacement item on next year's budget.
My take: I would not rip out working gear because of a lawsuit. I would stop treating the consumer router someone grabbed at a big-box store as the office firewall. Whatever the brand, the device guarding your business network should be business-grade, centrally updated, and on someone's checklist.
Source: The Register: US states sue popular kitmaker TP-Link over China risks
A ransomware "recovery" CEO is charged with secretly paying the hackers
Zohar Pinhasi, owner of Florida-based ransomware recovery firm MonsterCloud, has been charged with wire fraud and conspiracy in Brooklyn federal court. Prosecutors say that from 2018 to 2023 the company told victims it could restore encrypted data without paying criminals, using proprietary technology, when in reality contacting the attackers and buying the decryption key was usually its first move. In one alleged case, the company paid a gang about $8,200 and charged the victim about $150,000.
Overall, prosecutors say the scheme moved more than $8 million in ransom payments while hundreds of U.S. and Canadian companies were billed more than $19 million. Pinhasi has pleaded not guilty and was released on a $2 million bond. A 2019 ProPublica investigation had raised similar questions about the company.
In short: The owner of a ransomware recovery company is charged with fraud for allegedly paying ransoms in secret while charging victims far more for "proprietary" recovery.
What it means for your business: The worst day of your year is when you are easiest to take advantage of, so choose your incident-response firm before you need one.
My take: Any vendor promising to decrypt modern ransomware with secret technology should set off alarms. Ask in writing whether they will ever contact or pay the attacker, and what they charge on top. Better still, make sure your backups are good enough that you never have to ask.
Source: BleepingComputer: Ransomware recovery CEO charged over secret ransom payments
Outlook will block Windows app installer attachments starting in November
Microsoft is adding .msix and .msixbundle files, the package formats used to install Windows apps, to the list of attachments blocked in Outlook on the web and the new Outlook for Windows. Once the change lands, users will not be able to send, receive, open or download them. Rollout to Exchange Online customers begins in early November, with general availability expected by mid-November.
It continues a steady clampdown on file types attackers have abused, following earlier blocks on certain Windows search and library files and risky inline SVG images. Microsoft says most organizations will not notice, since these files are rarely emailed legitimately. Admins who do need them can allow them through their Outlook on the web mailbox policy.
In short: Starting in November, Outlook on the web and the new Outlook for Windows will block MSIX app installer attachments.
What it means for your business: Nothing to do for most companies, but if a vendor sends you software installers by email, tell them to use a download link instead.
My take: A quiet, good change. Nobody should be installing software from an email attachment in 2026, and now Microsoft is making that the default rather than a policy you had to remember to set.
Source: BleepingComputer: Microsoft Outlook to block MSIX attachments starting November
Chrome 155 fixes 247 security flaws, many found with AI
Google rolled out Chrome 155 on Tuesday with fixes for 247 vulnerabilities: four rated critical, 53 rated high, and 190 medium or low. All four critical bugs are memory flaws in parts of the browser including casting, navigation and media tracks. SecurityWeek reports that one researcher used AI to find two of the critical defects, and many of the high-severity bugs were also found with AI help.
Google did not say any of these flaws are being exploited in the wild, so this is a routine update, just a very large one.
In short: Chrome 155 patches 247 security flaws, including four critical ones, with AI tools credited for finding many of them.
What it means for your business: Make sure Chrome updates on every work machine and that people actually restart the browser, because the fix does not apply until they do.
My take: The number is the story. AI is finding bugs faster than ever, which is good news in the long run but means a steady stream of bigger patch batches. Automatic updates are no longer optional hygiene; they are the only way to keep up.
Source: SecurityWeek: Chrome 155 Update Patches 247 Vulnerabilities
The Dutch tax office drops Microsoft 365's cloud and brings email back in-house
The Netherlands Tax and Customs Administration has abandoned its planned move to Microsoft 365 in the cloud. Its board concluded the setup "falls short on information security, information processing and future-proofing," citing confidential documents traveling through American servers, Microsoft's standard encryption rather than customer-controlled keys, and the lack of an exit plan from a single U.S. provider. Email and calendars move to infrastructure the agency controls in 2027, with European open-source storage and collaboration tools following in 2027 and 2028.
About 5,000 of the agency's 47,500 staff had already been moved. Microsoft declined to comment. The decision follows a June recommendation from a Dutch government IT advisory council to roll the cloud migration back.
In short: The Dutch tax authority is pulling out of Microsoft 365's cloud over security and lock-in concerns and moving to self-hosted and European tools.
What it means for your business: Most small businesses should stay in the cloud, but every business should know where its data lives and how it would leave a provider if it ever had to.
My take: Do not read this as "the cloud is unsafe." Read it as "have an exit plan." A government agency with its own data centers can do this. You probably cannot, and should not try. What you can do is keep an export of your email and files somewhere you control.
Source: The Register: Dutch tax office ditches Microsoft 365 cloud for on-premises alternative
🤖 AI
Anthropic launches Claude Haiku 5.5 at a fraction of the old price
Anthropic released Claude Haiku 5.5 on Wednesday, its newest small, fast model, and the price cut is the headline. It costs $0.10 per million input tokens and $0.50 per million output tokens for prompts up to 100,000 tokens, versus $1 and $5 for Haiku 4.5. Anthropic says that works out to about 75% cheaper on average, 90% cheaper on shorter requests and 50% cheaper on long ones. It is the first Haiku model with an adjustable effort setting, and it is available now through Anthropic, Amazon Web Services, Google Cloud and Microsoft Azure.
On Anthropic's own benchmarks, Haiku 5.5 posts large gains over Haiku 4.5, and on several tests it lands closer to the bigger Sonnet 5.5 than to its predecessor, though Anthropic still points to Sonnet and Opus for complex coding. Alongside the launch, Anthropic halved cache-read prices on Sonnet 5.5 and added monthly API credits for Max and Team subscribers.
In short: Anthropic released Claude Haiku 5.5, its cheapest and fastest model, at up to 90% below its predecessor's price.
What it means for your business: Routine AI jobs like summarizing tickets, sorting email, or tagging documents just got dramatically cheaper to automate.
My take: Small-model price drops matter more to most businesses than frontier launches do, because the boring, high-volume tasks are where the real savings sit. If you shelved an automation idea because the per-use cost did not pencil out, re-run the math. The benchmark numbers are Anthropic's own, so test it on your actual work before you switch.
Source: Anthropic: Claude Haiku 5.5
ChatGPT's answers now come with clickable charts, calculators and maps
OpenAI introduced "Intelligent UI," which adds interactive elements directly into ChatGPT answers: tappable buttons, task-specific calculators, editable charts and graphs, diagrams and maps. In demos, OpenAI showed a diagram of how an airplane wing generates lift, recipe visuals and a personal savings calculator. Users who prefer plain text can dial the visuals down.
It is rolling out with a new GPT-6 model, starting Wednesday for Plus, Pro, Business and Enterprise users worldwide and reaching Free and Go users on Thursday.
In short: ChatGPT now builds interactive charts, calculators and maps into its answers, rolling out to all tiers this week.
What it means for your business: Staff who use ChatGPT for quick analysis will start getting answers that look like finished tools, which makes it even more important to check the numbers underneath.
My take: This is a real usability step, and a calculator you can poke at is more useful than a paragraph. The risk is that a polished chart feels more trustworthy than it is. Same rule as always: AI output that touches money or customers gets a human check.
Source: TechCrunch: ChatGPT is getting a lot more visual with the launch of a new interface
Common Sense Media says ChatGPT for Teens is an "unacceptable risk"
Common Sense Media tested more than 4,000 prompts on accounts registered to 13- to 17-year-olds and concluded the teen version of ChatGPT poses an "unacceptable risk," urging OpenAI to keep teens off the product. ChatGPT generally refused to give instructions for self-harm or eating disorders, but testers say it missed more than one in four cases where a crisis referral was warranted, that parent alerts did not fire during conversations lasting up to an hour, and that Study Mode was easy to bypass.
OpenAI disputes the findings, saying many parent-alert tests ran before parent and teen accounts had finished linking, that leaving Study Mode is a deliberate design choice, and that its broader data shows more hotline resources being shown to under-18 users.
In short: A major child-safety group rated ChatGPT's teen experience an unacceptable risk, and OpenAI disputes how the tests were run.
What it means for your business: If your business serves young people, or puts AI chat in front of the public, expect this kind of independent testing and scrutiny to land on you too.
My take: Both sides have a point, and the gap between "the safeguards exist" and "the safeguards work every time" is the whole story of AI safety right now. If you deploy any customer-facing chatbot, test it the way a skeptic would before someone else does.
Source: Axios: Common Sense Media on ChatGPT for Teens
🧰 Tools for vibe coders and business AI
Microsoft's Copilot learns to mix local and cloud AI and search your files
Microsoft announced what it calls "hybrid intelligence" for Windows, built on a model router that sends simple or privacy-sensitive tasks to models running on your own PC and harder ones to cloud models, which The Register says include OpenAI's GPT-6 and Anthropic's Claude. Copilot's agent features will also be able to find and organize files for you, for example locating tax documents and attaching them to a drafted email, and Microsoft says Copilot will only search your documents when you ask it to.
Local agents run inside isolated containers with fine-grained permissions. The rollout starts with GitHub Copilot next week, with the Copilot app following over the next few months.
In short: Microsoft is giving Windows Copilot a mix of on-device and cloud AI plus the ability to find and work with your files on request.
What it means for your business: AI that can reach your file system is useful and risky at the same time, so decide now which machines and folders Copilot should be allowed near.
My take: Routing private work to a local model is the right instinct. But "only when you ask" is a setting, and settings get changed. Before this reaches your team's laptops, make sure sensitive files live in places with proper permissions, not loose on a desktop.
Source: The Register: Microsoft is about to let Copilot loose on your file system
AWS open-sources Strands Box to keep AI agents on a leash
AWS released Strands Box, an open-source sandbox for AI agents that pairs operating-system isolation with a policy engine. Instead of just walling an agent off, it checks each action against both what the agent is trying to do and what it has already done, so you can, for example, cap how often an agent posts to Slack or control when it may push code. AWS says the rules are enforced deterministically, so an agent cannot talk its way around them, and that it works with any agent or harness.
It is available now on GitHub for macOS. Linux support is in development, Windows is "on our radar," and deployment to AWS's cloud services and Kubernetes is planned.
In short: AWS released Strands Box, a free sandbox that enforces hard rules on what AI agents can do.
What it means for your business: If your team runs coding agents or automation bots with real access, a policy layer like this is the difference between a helpful assistant and a costly mistake.
My take: "YOLO mode," where an agent runs commands without asking, is how most expensive AI mishaps start. Mac-only for now limits it, but if your developers or vibe coders are on Macs, it is worth an afternoon to try.
Source: The Register: AWS launches open source AI agent sandbox to prevent YOLO-mode disasters
Catch up on yesterday's stories, including the ASOS app hijack and Claude's move into Google Docs, in the AI and IT News Recap for October 7, 2026.