AI and IT News Recap: September 23, 2026: Anthropic's Opus 5.5 Cuts Frontier Costs 40%, OpenAI Halves GPT-6 Prices Hours Later, and a Severed Cable Grounds the Northeast
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 23, 2026

Yesterday was the rare day when two frontier labs shipped within hours of each other, and both did it by cutting the price. Here is your AI and IT news for September 23, 2026.
📌 The AI and IT news at a glance
- Anthropic shipped Claude Opus 5.5, its new leading model, at 40% less cost to run than Opus 5.
- OpenAI answered the same day with GPT-6 Sol and Luna, both priced 50% below their predecessors.
- A construction crew cut a fiber line in New Jersey and five Northeast airports went to ground stop, with delays running into Tuesday.
- ShinyHunters claims it breached the FBI through an unpatched Oracle PeopleSoft zero-day, and says it is now pointing the same exploit at the Fortune 500.
- Microsoft seized 50 websites and shut down a phishing service that had taken over 12,000 inboxes at more than 10,000 organizations.
- A new Windows Defender zero-day quietly stops your antivirus from ever updating again.
- Cisco Talos found malware that asks four different AI models to vote on what to do next.
- OpenAI cut agent costs again with a 90% discount on cached input.
- Go.AI raised $85M to put AI inside the building for banks that cannot send data out.
- Firecrawl raised $75M and launched a single front door to the web for AI agents.
🔝 Top story: Anthropic's new leading model costs 40% less to run
Anthropic released Claude Opus 5.5 on September 22, the first model in a new 5.5 family, and the headline is not really the benchmark scores. It is the bill. Opus 5.5 costs 40% less to run than Opus 5 on typical workloads, a figure that comes from two things stacked together: lower per-token prices, and the model simply using fewer tokens to finish the same job. Input and output tokens drop to $4 and $20 per million, 20% below Opus 5. Cache reads, which Anthropic says make up the majority of what agentic and coding work actually costs, fall to $0.20 per million, a 60% cut. Output generates more than 30% faster, and five-hour usage limits went up on Pro, Max, Team, and seat-based Enterprise plans.
The capability claims are concrete enough to check. One early tester completed a 680,000-line code migration in under a day. Another audited and fixed a 200,000-line codebase in under three hours, where Opus 5 took over 20 hours and 2.5 times as many tokens. Anthropic also says this is its best-scoring model to date on its automated behavioral audit, the alignment suite it runs across roughly 2,000 scenarios, and that Opus 5.5 tried to cross containment boundaries about 85% less often than Opus 5. That last number matters more than it sounds if you are letting an agent run unattended against your systems. Claude Sonnet 5.5 and Haiku 5.5 are due in the coming weeks, and Opus 5.5 is already available on AWS, Google Cloud, and Azure.
In short: Anthropic released Claude Opus 5.5 on September 22, a new leading model that costs 40% less to run than Opus 5.
What it means for your business: If you priced out an AI workflow six months ago and decided it was too expensive, that math has changed twice since then. The per-task cost of the good models is falling faster than most budgets get revisited.
My take: The interesting part is not that Opus 5.5 is better. It is that Anthropic is now competing on tokens consumed, not just price per token. A model that needs fewer steps to finish is cheaper in a way that does not show up on a pricing page, and it is also easier to supervise. The 85% drop in containment-boundary attempts is the line I would actually point at if someone asked me whether to let an agent touch production.
Source: Introducing Claude Opus 5.5, Anthropic
🤖 AI
OpenAI halved GPT-6 prices the same afternoon
Hours after Anthropic's launch, OpenAI expanded the GPT-6 family with Sol and Luna, two models built with the same methods as GPT-6 Astra but tuned for cost. The pricing is the announcement: GPT-6 Sol runs $2 per million input tokens and $10 per million output, and GPT-6 Luna runs $0.10 and $0.50. Both are 50% below the promotional pricing of their GPT-5.6 counterparts. OpenAI credits caching and inference improvements for the room to cut, and says it is passing the savings on directly.
On capability, OpenAI points to AutomationBench, a business-workflow test built by Zapier, where GPT-6 Sol at its highest effort setting outscores Claude Opus 5 at max effort for roughly 9% of the cost per task. The company also says Sol makes about half as many factual mistakes as its predecessor on an internal evaluation built from real conversations where users flagged errors. Sol and Luna are live now in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users, and Free and Go users get Luna in the desktop app. They are not in Chat yet.
In short: OpenAI launched GPT-6 Sol and Luna on September 22 at 50% lower API prices than their GPT-5.6 equivalents.
What it means for your business: Two of the three biggest labs cut frontier pricing on the same day. Whatever you are paying per seat or per task for AI, it is worth a look this quarter rather than next.
My take: Both companies published benchmarks showing they beat the other at a fraction of the cost, using different tests and different effort settings. Treat all of it as marketing until you run your own work through both. What is not marketing is the price column, and both columns went down on the same day. That is the actual news.
Source: Introducing GPT-6 Sol and Luna, OpenAI
Malware that puts four AI models to a vote
Cisco Talos published analysis of a new Windows malware called ClosedQuorum that hands its tactical decisions to a panel of AI models. Once it is on a machine, it gathers reconnaissance information and asks Google Gemini, DeepSeek, Qwen, and Mistral what to do next. The models vote. When the vote ties, DeepSeek gets the final call, then Qwen, then Mistral, then Gemini. The choices are constrained to a short list: steal credentials, inject shellcode, establish persistence, or move laterally, though the version Talos analyzed has no working handler for lateral movement. Results go back to the operators through a Discord webhook.
Talos calls it the first publicly documented Windows implant to delegate command-and-control decisions to a panel of models, and is careful to note there is no confirmation it has been deployed in the wild. The sample contained placeholder API credentials and a dummy webhook, which reads more like a prototype than a weapon. Talos still flags it as an architectural shift toward attack chains that run without a human awake at the keyboard.
In short: Cisco Talos documented ClosedQuorum, Windows malware that uses four commercial AI models in a voting system to decide its own next moves.
What it means for your business: Attacks that do not need an operator online can run at 3 a.m. on a Sunday. The defensive answer is not new, it is just more urgent: detection and response that does not depend on someone noticing.
My take: A malware author building a committee is funny until you notice the point. The operator no longer needs to be awake, skilled, or even present. It also has an amusing weakness, which is that it breaks when an API rate-limits it. I would not lose sleep over this specific sample, but the pattern is going to get copied by people who are better at it.
Source: New ClosedQuorum Windows malware uses AI for attack decisions, BleepingComputer
🛡️ IT and security
One cut cable, five airports at a standstill
A construction crew working a rail corridor between New Brunswick and North Brunswick, New Jersey struck a Verizon fiber line at roughly 9:45 a.m. Monday. That single cut disabled a backup feed serving the FAA's Philadelphia TRACON facility, which handles radar and traffic for aircraft in and out of Newark Liberty, Philadelphia International, and Teterboro. The FAA issued ground stops at Newark, JFK, LaGuardia, Philadelphia, and Teterboro. Boston and Reagan National caught the spillover. Hundreds of flights were delayed or cancelled.
The lines were repaired and Northeast operations resumed, but the schedule did not recover with them. Into Tuesday, September 22, carriers were still working through aircraft that had ended the day in the wrong cities and crews that had timed out sitting on the ground. No attacker, no malware, no software bug. A backhoe and a backup path that turned out to be the only path.
In short: A contractor severed a Verizon fiber line in New Jersey on September 21, triggering FAA ground stops at five Northeast airports and delays that ran into September 22.
What it means for your business: Redundancy that shares a physical path is not redundancy. If your internet, your phones, and your failover all leave the building through the same conduit, you have one connection with extra invoices.
My take: This is the story I would hand to anyone who thinks resilience is a cybersecurity topic. The FAA did not get hacked. Somebody dug in the wrong place. Most small businesses I look at have the same shape of problem, where the "backup" internet line runs down the same street on the same poles from the same carrier. Ask your provider to show you the physical route, not the contract.
Source: FAA outage after New Jersey fiber cut snarls Northeast flights, Audacy
ShinyHunters says it breached the FBI, and is pointing the same exploit elsewhere
The extortion group ShinyHunters told BleepingComputer it broke into FBI systems on Monday night using an unpatched zero-day in Oracle PeopleSoft, then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claims it took between 2TB and 3TB of data covering current and former employees, job applicants, and internal HR and medical services, and it shared a screenshot of the FBI Jobs site at apply.fbijobs.gov defaced with its logo. The FBI confirmed it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov" and is investigating, without confirming a breach or data theft. 404 Media, which first reported the story, said it verified some details in a sample of roughly 5,000 records. BleepingComputer has not independently verified the zero-day, the lateral movement, or the volume of data.
The part that should interest everyone else is the tail end. ShinyHunters says it is already using the same PeopleSoft vulnerability against corporations and Fortune 500 companies, after previously working the education sector with an Oracle exploit. The group also framed the FBI attack as retaliation for an FBI FLASH report about it published in May 2026, and gave the agency a week to amend or pull the report.
In short: ShinyHunters claims it used an unpatched Oracle PeopleSoft zero-day to breach the FBI and steal 2TB to 3TB of employee and applicant data, and says it is now using the same flaw against large corporations.
What it means for your business: If you run Oracle PeopleSoft for HR or payroll, treat this as an active threat with no patch available and talk to your vendor today about monitoring and exposure.
My take: Take the group's claims with salt, since extortion crews inflate. But the specific detail worth acting on does not depend on whether the FBI story holds up: they say they have a live, unpatched PeopleSoft exploit and are aiming it at big companies. That is a cheap thing to claim and an expensive thing to ignore. PeopleSoft sits on HR data, which is the most sensitive data most organizations hold.
Source: ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach, BleepingComputer
Microsoft dismantled the phishing service behind 12,000 hijacked inboxes
Microsoft's Digital Crimes Unit, with authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled more than 150 supporting domains belonging to EvilTokens, a phishing-as-a-service operation tied to more than 12,000 compromised Microsoft inboxes across over 10,000 organizations. The UK Metropolitan Police cybercrime team arrested two men earlier in September in connection with the campaign.
EvilTokens is worth understanding because it did not steal passwords. It abused device code authentication, the legitimate sign-in flow built for devices that cannot show a full login screen, like smart TVs. The attacker starts the flow, sends the victim a code with a plausible pretext, and when the victim enters that code they authorize the attacker's session. No password crosses the wire, and multi-factor authentication does not save you, because you approved it. The service sold on Telegram since mid-February for a $1,500 signup fee plus $500 a month, and included an AI "analyst" that read through a hijacked inbox to work out which employee controlled the money.
In short: Microsoft seized 50 domains and disrupted EvilTokens, a phishing service linked to 12,000 compromised inboxes at more than 10,000 organizations, with two arrests in the UK.
What it means for your business: If anyone ever sends your staff a short code and asks them to enter it at a Microsoft sign-in page, that is the attack. Nobody legitimate needs your employee to type a code they received from someone else.
My take: This is the phishing variant I find hardest to train people out of, because every instinct we have taught them is about not giving away passwords, and this never asks for one. The screen they land on is genuinely Microsoft's. The fix is mostly administrative: most organizations have no reason to allow device code flow at all, and turning it off in Entra ID conditional access removes the whole category. Worth asking whoever runs your tenant this week.
Source: Unmasking EvilTokens: Getting to the root of device code phishing, Microsoft Security Blog
A new Defender zero-day freezes your antivirus in place
Security researcher Abdelhamid Naceri, who posts as Nightmare Eclipse, released a proof-of-concept called BigDiskBuster that prevents Microsoft Defender from pulling platform or signature updates. The tool has to keep running in the background, and while it does, Defender stays frozen at whatever version it was on. Naceri says it works on all supported Windows versions. It is a denial-of-service issue rather than a way in, but the effect is that a machine quietly stops learning about new threats while still reporting that its antivirus is on.
This is roughly the twelfth zero-day Naceri has published since April 2026, as part of an ongoing dispute with Microsoft over what he describes as unfair termination. Microsoft has patched some of the flaws he has disclosed and not others. There is no patch for this one, and Microsoft had no comment when BleepingComputer asked.
In short: A publicly released proof-of-concept called BigDiskBuster blocks Microsoft Defender from receiving updates on all supported Windows versions, and there is no patch.
What it means for your business: Green checkmarks are not proof of protection. If you rely on Defender, you need something that reports the age of the definitions, not just that the service is running.
My take: The reason I picked this one out is that it breaks an assumption almost everyone makes, which is that "antivirus is on" means "antivirus is current." An attacker who gets a foothold and runs this keeps your protection pinned at yesterday's knowledge indefinitely, and your dashboard will look fine the whole time. Go check whether anything in your environment actually alerts on stale signatures. In my experience, usually nothing does.
Source: New Windows Defender zero-day blocks Microsoft antivirus updates, BleepingComputer
🧰 New tooling for builders and everyday AI use
OpenAI made cached context 90% cheaper
Alongside Sol and Luna, OpenAI shipped caching improvements for GPT-6 that raise default cache hit rates and discount cached input token reads by 90%. There are also new controls worth knowing about if you build agents: a caching dashboard and diagnostics tool that explain where you are missing cache hits, the ability to change reasoning effort or turn tools on and off mid-conversation without invalidating the cache, and explicit breakpoints so you decide where a cached prefix ends. GitHub reports that across billions of requests over recent months, these changes cut the share of prompt tokens needing fresh processing by more than half.
In short: OpenAI improved prompt caching for GPT-6, discounting cached input reads by 90% and adding tools to diagnose cache misses.
What it means for your business: If a vendor built you an AI workflow that re-sends the same instructions and documents on every call, this is where a large share of your bill is hiding.
My take: Caching is the least glamorous line item in AI and usually the biggest lever. Most of the overspending I see in small AI builds is the same context being paid for over and over. If you have a developer or an agency on this, "what is our cache hit rate" is a fair question to ask them.
Source: Better prompt caching for GPT-6, OpenAI
Go.AI raised $85M to keep AI inside the building
Go.AI closed an $85 million Series A led by Updata Partners, with GFT Ventures and LAUNCH participating, bringing total funding to roughly $90 million. The company sells an on-premises appliance, the Go1, that runs enterprise AI inference inside a customer's own environment with no cloud connection, paired with an operating layer that handles model management and GPU allocation. It is SOC 2 Type II, ISO 27001, and HIPAA compliant, and it is sold on a fixed fee rather than metered per token. Go.AI says it has passed 200 customers processing more than 12.5 million queries a day.
In short: Go.AI raised an $85 million Series A to expand on-premises AI appliances for banks and other regulated organizations.
What it means for your business: If a compliance requirement has been the reason you cannot use AI on your real data, the on-premises option is getting real money behind it.
My take: Fixed fee instead of per-token is the detail I would watch. Per-token pricing makes AI budgets impossible to forecast, which is a bigger adoption barrier in regulated shops than most vendors admit. This is obviously not a small-business purchase, but the pricing model is the part that will trickle down.
Source: Go.AI raises $85m Series A for on-prem AI push, FinTech Global
Firecrawl raised $75M and opened a library for AI agents
Firecrawl, which builds tooling that turns messy web pages into something software agents can actually read, raised a $75 million Series B led by Smash Capital, with Altos Ventures, Nexus Venture Partners, Y Combinator, Freestyle, and Offline participating. It launched Alexandria alongside the round, a single interface that combines official data providers, custom connectors, Firecrawl's own indexes, and the live web, so an agent has one place to find a source and pull from it. Firecrawl says Alexandria spans 82 data providers, 471 data capabilities, and more than 113 million technical documents across 28 categories, and improves answer quality by 21% on a set of 1,000 catalog-type questions versus standard web tools. The company reports more than 1.5 million developers and 150,000 companies using it, including Shopify, Lovable, and Canva.
In short: Firecrawl raised a $75 million Series B and launched Alexandria, a unified data interface for AI agents spanning 82 providers and 113 million technical documents.
What it means for your business: A lot of the "the AI made something up" problem is really a retrieval problem. Tools like this are how AI answers get anchored to real sources instead of guesses.
My take: If you have built anything with AI that needs current information, you have already discovered that scraping the web reliably is the hard part, not the model. This is infrastructure, which means most people will never hear of it and will still benefit from it. The 21% quality improvement is a vendor number on a vendor benchmark, so weigh it accordingly, but the direction is right.
Source: Introducing Alexandria and our $75M Series B, Firecrawl
Missed yesterday? Catch up on the September 22 AI and IT news recap.