AI and IT News Recap: October 9, 2026: A Drone Strike on One Yandex Data Center Ripples Across Russia, Ransomware Takes Down a SoftBank Cloud, and Google Gives Gemini Agents Their Own Email

By Noah Smith, Owner & Consultant, KeyChange Technologies · October 9, 2026

Pen-and-ink sketch of a long night-market street whose stall lanterns all hang from one cord running up a hill to a single smoking brick building, with most lanterns gone dark and puzzled shopkeepers looking up

Friday's AI and IT news is a lesson in concentration risk: one building in rural Russia, one cloud region in Japan, and one agent in your inbox. Here is what matters for your business, in about six minutes.

📌 The AI and IT news at a glance

  • A drone strike on one Yandex data center ripples across Russia's internet, hitting cloud, mail, payments, railways and banks.
  • Ransomware takes down a SoftBank-owned cloud used by 495 companies and local governments in Japan.
  • The FBI and six allies expose a Chinese contractor's hacking kit, including password-spraying tools aimed at Microsoft 365 and a portal for browsing stolen email.
  • Cheap Android phones are shipping with malware already inside, across more than 150 countries.
  • An AI hacking agent helped raid South Korean banks, and the attacker left their Claude Code session logs in an open folder.
  • Google gives its Gemini business agent its own email address, calendar and audit trail.
  • Anthropic launches a Cyber Mission with 11 founding partners and a free vulnerability scanner for open-source projects.
  • Anthropic rewrites its usage policy, banning fake-front campaigns, surveillance tools and sustained abuse of the model.
  • Anthropic commits $150 million to the federal Genesis Mission science program.
  • OpenAI breaks up a Russian fake think tank that hired real local staff who never knew who they worked for.
  • Microsoft Teams is getting deepfake detection and impersonation warnings in November.
  • Google ships an offline AI meeting note-taker for the Mac.

🔝 Top story

A drone strike on one Yandex data center ripples across Russia's internet

On Thursday, drones struck a Yandex data center in Sasovo, in Russia's Ryazan region, and the facility was shut down after a large fire. Tom's Hardware describes the site as one of Yandex's five major data centers, holding tens of thousands of servers and two of the company's three AI supercomputers. Yandex warned that some services might be unavailable and told Yandex Cloud customers to move workloads to other availability zones, while insisting that key consumer services stayed up.

The ripple effect is the story. Yandex Mail, Disk, Documents, Pay, Market and Yandex Cloud all reported problems, and so did businesses that simply rent space or services from Yandex: Russian Railways, the property site Cian, the 1C business software platform, regional government websites, and news outlets including RIA Novosti and Interfax, which blamed an "infrastructure partner." Corporate disruptions were also reported at T-Bank, Ozon and Wildberries. The outage tracker Detector404 logged more than 58,000 complaints in 24 hours. Reports note it is still unclear whether the drones were aimed at the data center or the adjacent factory, and whether the supercomputers were damaged.

In short: A drone strike and fire shut down one of Yandex's main data centers on October 8, disrupting cloud, mail, payment and banking services across Russia.

What it means for your business: Many companies that never chose Yandex went dark anyway, because a vendor of a vendor ran on that building. Your own exposure works the same way, whether the cause is a drone, a flood, a fiber cut or a fire.

My take: Most of us will never have to plan for drones, but every one of us should know which of our critical apps all sit in one cloud region. "Multi-zone" only helps if someone actually set it up, so ask your key vendors where your data lives and what happens when that building is gone. Yandex had alternate zones; the customers who had not used them were the ones scrambling.

Source: Tom's Hardware


🛡️ IT and security

Ransomware takes down a SoftBank-owned cloud used by 495 companies and local governments

IDC Frontier, a SoftBank subsidiary, first reported unauthorized access and outages in its IDCF Cloud service this week, and has now confirmed that the disruption in its "East Japan Region 1" was a ransomware attack. The company shut down the affected network and systems and disabled customer access to management consoles in every region while it checks their security. About 495 companies and local governments use the affected service.

The attacker claims it got through the region's infrastructure in seven minutes, encrypted 225 databases holding 3.6 petabytes, reached 239 hypervisors, sealed 16,000 virtual machine disks and wiped more than 554,000 snapshots. Those numbers come from the attacker and have not been verified by IDC Frontier, which says it is still investigating the cause and scope. Separately, Nissui Logistics, part of seafood giant Nissui, reported an outage tied to a third-party data center, though no link to IDCF has been confirmed.

In short: A ransomware attack shut down part of IDC Frontier's IDCF Cloud in Japan, cutting off hundreds of business and government customers.

What it means for your business: "It's in the cloud" is not a backup plan. If your provider's own systems get encrypted, your data, your snapshots and your console can all be out of reach at the same time.

My take: The scariest line in the attacker's claim is "554,153 snapshots wiped." If that is even partly true, a lot of customers just learned their backups lived in the same blast radius as their servers. Keep at least one copy of anything you cannot lose somewhere your main cloud provider cannot touch, and test restoring it.

Source: BleepingComputer


The FBI and six allies expose a Chinese contractor's hacking kit, including a portal for reading stolen email

The FBI and agencies in six other countries published a joint advisory on Thursday about hacking activity tied to Integrity Technology Group, a Beijing-linked company already under U.S. and UK sanctions. The FBI seized seven domains used to run two of its tools: MicroScan, a scanner packed with more than 1,300 attack scripts, and FishHub. Targets named in the advisory include a South Carolina power company, airports in Japan and Poland, Taiwanese energy companies and universities, plus U.S. government, healthcare, manufacturing and IT organizations. The FBI did not confirm which of the named targets were actually breached.

The details read like a playbook for attacking ordinary offices. The group used a password-spraying tool called EBurst aimed at Microsoft 365 and Exchange, fake login pages, and a tool that pulls mail out of Microsoft 365. Investigators also found a web application that let third parties browse stolen email accounts just by changing a web address. The advisory lists eight exploited flaws and urges organizations to require MFA, review cloud apps that can read mail and files, and replace unsupported products.

In short: Western agencies seized domains and published the tools of a sanctioned Chinese firm whose hackers spray passwords at Microsoft 365 and sell access to stolen inboxes.

What it means for your business: Nation-state crews still get in the boring way: guessed passwords, no MFA, and apps that were given permission to read email and never reviewed.

My take: The "portal for stolen email" is the detail I would share with your team. Your inbox is not just read by the attacker; it can be resold to whoever is paying. Turn on MFA everywhere, block legacy sign-in methods in Microsoft 365, and pull a list of third-party apps with mail access this month.

Source: The Hacker News


Cheap Android phones are shipping with malware already inside

Bitdefender researchers say thousands of low-cost Android phones in more than 150 countries came with malware baked into the firmware, a framework they call Midnight Mimosa. Named models include the Doogee S200 X, Doogee Fire 3 Max and Cubot KINGKONG X, and some infected phones were sold as fake Samsung and Apple products. The most affected countries include Mexico, France, Italy, the United States and Germany.

Because it runs as a system app, the malware can silently install and remove apps, grant itself permissions and run code downloaded later. It generates ad fraud and can turn the phone into a "residential proxy" that relays other people's internet traffic, although Bitdefender could not confirm active traffic forwarding in its tests. It even disables the Play Store temporarily to dodge Google's own scanning, and removing it usually takes a firmware-level cleanup.

In short: Bitdefender found malware preinstalled on budget Android phones sold in more than 150 countries, tampered with somewhere in the supply chain.

What it means for your business: A bargain phone used for work email or MFA codes can be compromised before it ever leaves the box, and no app you install will fix it.

My take: If you hand out phones or let staff use their own for work, set a floor: known brands, bought from real retailers, still receiving security updates. The $40 savings on an off-brand device is not worth a phone that might be relaying a stranger's traffic through your office Wi-Fi.

Source: BleepingComputer


An AI hacking agent helped raid South Korean banks, and the attacker left their Claude logs in an open folder

CrowdStrike Intelligence says a financially motivated attacker used ARTEX, an open-source "agentic" penetration-testing tool developed in China, to automate attacks on South Korean financial firms from late September into early October, stealing data. The setup ran mainly on DeepSeek, with Z.ai and Grok models as backups. CrowdStrike found it after spotting open directories on a Hong Kong server that exposed the attacker's ARTEX configuration files and Claude Code session histories. In those logs, the attacker also asked Claude where stolen Korean breach data is usually sold.

This lands days after South Korea's financial regulator launched emergency on-site investigations into breaches at Shinhan Bank, KB Kookmin Bank and Hana Bank, where local reports put Shinhan's exposure at about 25,000 customers. Earlier reporting had flagged an ARTEX string on an attack server, but neither the banks nor authorities have confirmed ARTEX was used in those specific breaches, and CrowdStrike has not attributed the campaign to a named group. ARTEX's developer said the misuse violated the tool's purpose and has taken the project closed source.

In short: CrowdStrike says an attacker used an AI agent toolkit to automate data theft from South Korean financial firms.

What it means for your business: AI does not invent new break-ins; it lets one person try the old ones against far more targets, far faster. The basics now have to hold up under that volume.

My take: This is my one technical pick today, because it is a clean real-world example of the "AI-driven attacker" everyone has been predicting. The irony is that the attacker got caught by leaving files in an open folder, which is the same mistake that gets small businesses breached. Speed cuts both ways.

Source: The Hacker News


🤖 AI

Google gives its Gemini business agent its own email address, calendar and audit trail

At a Google Cloud event on Thursday, Google unveiled a single agent inside Gemini that can both answer questions and carry out multi-step work, rolling out to businesses first with consumers to follow at an unannounced date. You give it a goal rather than step-by-step instructions, and it plans the work, delegates to sub-agents and connects to internal systems. It plugs into Google Workspace, Microsoft 365, Slack, Jira, Confluence, Snowflake and other tools, supports MCP servers, and lets users pick other models, including Anthropic's Claude.

The notable twist is identity. The agent gets its own Workspace account with an email address and organizational context like team membership, approvers and calendars, so staff can email it, tag it or add it to group chats, and its actions are logged to an audit trail under its own name. Google also added spending controls such as smart model routing and real-time spend caps. Early testers include Shopify, PayPal and On. TechCrunch did not report plan names or prices.

In short: Google launched a unified Gemini agent for businesses that does tasks across Workspace, Microsoft 365 and other apps under its own account.

What it means for your business: AI agents are becoming coworkers with logins, which means they need the same onboarding, permissions and offboarding you give a new hire.

My take: Giving the agent its own identity and audit trail is the right call, and I wish every vendor did it. Before you switch it on, decide what it can touch and who approves its work, because an agent with an inbox can also be phished. Start it on a narrow job, watch the logs for a month, then widen.

Source: TechCrunch


Anthropic launches a Cyber Mission, with a free vulnerability scanner for open-source projects

Anthropic announced the Anthropic Cyber Mission on Thursday, a long-term effort to help defenders. It starts with a Critical Infrastructure Defense Program that gives trusted security firms access to frontier Claude models, on-site Anthropic engineers and threat research, focused on systems like power grids, water and transportation. The 11 founding partners include CrowdStrike, Palo Alto Networks, Accenture, Booz Allen, Deloitte, Dragos and Rockwell Automation.

The second piece is OSS Scanner, a free, opt-in service that periodically scans open-source projects with Anthropic's most capable models and sends maintainers reports with a proof of concept and a suggested fix. Reports go out without human review, and Anthropic says it expects more than 90% of them to be real issues. Anthropic is also funding groups behind widely used open-source code, including the Python Software Foundation, OpenSSF and the Apache Software Foundation.

In short: Anthropic launched a cyber defense program for critical infrastructure and a free AI scanner for open-source code.

What it means for your business: Nearly every app you use is built on open-source parts, so faster bug-finding and fixing upstream eventually means fewer emergency patches downstream.

My take: The 90% accuracy claim matters, because Google just paused part of its open-source bug bounty over a flood of junk AI reports. If Anthropic's scanner really sends mostly real bugs with fixes attached, maintainers will welcome it. If not, it adds to the noise. Worth watching what maintainers say in a few months.

Source: Anthropic


Anthropic rewrites its usage policy, banning fake-front campaigns, surveillance tools and sustained abuse of the model

Anthropic published an updated Usage Policy on Thursday that takes effect November 12. A new section bans deceptive campaigns and artificial activity, pulling together rules on fake accounts, fabricated news sites and influence operations, whether political or commercial. The surveillance section now explicitly bars building surveillance tools and using Claude to decide who to investigate, arrest or charge, while listing consent-based uses like fraud monitoring, content moderation and journalism as allowed.

There are also new rules for Claude controlling physical hardware: a qualified operator must be able to stop it, and the equipment must fall back to a safe state if Claude disconnects. The policy adds a ban on sustained, needless cruelty toward Claude, which Anthropic says targets extreme cases rather than frustration, pushback or dark creative themes. On elections, personalized voter outreach is no longer blanket-prohibited, opening the door to things like multilingual ballot notices from election officials.

In short: Anthropic's new usage policy, effective November 12, tightens rules on influence campaigns, surveillance and hardware control.

What it means for your business: If you build on Claude, especially for marketing automation, monitoring or anything that moves physical equipment, review the new language before November 12.

My take: For most businesses nothing changes, and Anthropic itself says most of this clarifies existing enforcement. The part to read closely is the hardware rule if you are wiring AI into anything with motors. "Someone can hit stop, and it fails safe" is good practice whether or not a policy requires it.

Source: Anthropic


Anthropic commits $150 million to the federal Genesis Mission science program

At a White House science summit on Thursday, Anthropic committed $150 million over three years to the Genesis Mission, the federal initiative using AI to speed up research. The money will put Claude, Claude Code and API credits in the hands of scientists at more than 15 agencies, including the Department of Energy and its national labs, NASA, the National Institutes of Health and the National Science Foundation, across several hundred research projects.

Anthropic says it will also work with agencies on priorities like fusion energy and quantum computing, and provide training and support for agencies running their first AI projects. Anthropic first partnered with the Department of Energy on the Genesis Mission in December.

In short: Anthropic pledged $150 million over three years to bring Claude to federal science agencies through the Genesis Mission.

What it means for your business: Not much this quarter, but federal labs adopting AI at scale tends to speed up the tools and research that later reach the private sector.

My take: This is part science and part positioning, as every AI lab competes to be Washington's preferred partner. Either way, more AI in national labs is good for research. I would not make any decision based on it.

Source: Anthropic


OpenAI breaks up a Russian fake think tank that hired real local staff

OpenAI published a threat report on Thursday describing two covert influence operations it disrupted. The bigger one, which OpenAI calls "Dark Clark," ran a fake research outfit called the Social Research Center, fronted by an invented persona named "Mia Clark," that targeted Latin America to undermine Ukraine and sway politics in Argentina and Bolivia. Local staff apparently did not know they were working for a Russian operation. OpenAI rates it Category 5 on its impact scale, the first it has disrupted at that level.

The operators mainly used ChatGPT to write internal reports, and occasionally to produce fakes such as a forged letter, audio scripts and a contract. A second, Iran-origin operation used seven fake journalist personas to pitch almost 100 articles about the U.S.-Iran conflict to small and mid-sized outlets. OpenAI banned the accounts and shared its findings with authorities and industry partners.

In short: OpenAI disrupted Russian and Iranian influence operations that used fake think tanks and fake journalists to place content in real outlets.

What it means for your business: Fake organizations with real-looking staff, websites and paperwork are getting cheaper to build, so verifying a new partner, vendor or "journalist" matters more than ever.

My take: The line that sticks with me is that the hired staff did not know who they worked for. Swap "think tank" for "supplier" or "recruiter" and you have a business fraud risk. A quick video call and a check of company registration records still beat a polished website.

Source: OpenAI


🧰 Tools for vibe coders and business AI

Microsoft Teams is getting deepfake detection and impersonation warnings

Microsoft added two Teams meeting security features to its Microsoft 365 roadmap on Thursday. The first lets certified third-party providers analyze meeting audio and video for synthetic or manipulated content and surface the alerts inside Teams with in-meeting controls. The second warns users when Teams spots a possible impersonation attempt by a meeting organizer or participant, with risk indicators to help judge who is really on the call.

Both are in development, with general availability expected in November 2026. Microsoft has not named the detection vendors, and it is not yet clear which licenses include the features or whether third-party detection costs extra.

In short: Teams will add deepfake detection through outside vendors and built-in impersonation warnings, expected in November.

What it means for your business: The "CEO on a video call asking for a wire transfer" scam is real, and help is coming to the tool many offices already use.

My take: Welcome news, but do not wait for it. The cheapest deepfake defense is a rule: any payment or credential request made on a call gets confirmed through a second channel you already trust. Write that rule down now.

Source: BleepingComputer


Google ships an offline AI meeting note-taker for the Mac

Google released AI Edge Foresight, a Mac app for Apple Silicon that transcribes meetings, writes notes and answers questions using AI that runs on the device. You jot shorthand on one side of the screen while AI-generated notes build on the other, and you can chat with a Gemma 4-powered assistant during the meeting. You can also load PDFs, Google Docs, Office files and other documents into a knowledge base it draws on in real time.

Because it runs locally, it works fully offline, including for in-person meetings. TechCrunch did not report pricing, and Google has not announced a cloud or Windows version.

In short: Google launched AI Edge Foresight, an on-device meeting note-taker for Macs that works without an internet connection.

What it means for your business: Local AI note-takers keep sensitive meeting audio off third-party servers, which can make the legal and privacy conversation much simpler.

My take: For client meetings, HR conversations or anything under NDA, "the recording never leaves this laptop" is a strong selling point. Still tell people you are transcribing, since recording consent laws apply no matter where the AI runs.

Source: TechCrunch


Missed yesterday's recap? Catch up on the October 8 AI and IT news recap, with the FBI's FortiBleed warning, the TP-Link lawsuits and Claude Haiku 5.5.