AI and IT News Recap: September 25, 2026: The White House Puts Itself First in Line for New AI Models, Seven Forgotten Microsoft 365 Accounts Open the Door, and Gemini Starts Making Phone Calls
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 25, 2026

A quiet Thursday on the outage front, and a loud one everywhere else. Here is your AI and IT news for Friday, September 25, 2026.
📌 The AI and IT news at a glance
- The White House asked OpenAI and Anthropic to keep new frontier models away from the UK's safety testers until the US government has looked first.
- Google shipped Gemini 3.8 Live with Live Avatar, a talking, lip-synced face for enterprise AI, generally available today.
- Google, OpenAI and Anthropic are moving to stand up their own frontier-AI standards body, without asking Congress.
- A password-spraying crew hit 5,714 Microsoft 365 accounts across 28 tenants and got into exactly seven, every one of them a forgotten service account with no MFA.
- A pre-authentication SQL injection flaw in Roundcube webmail is being actively exploited.
- Mac info-stealer MacSync is now hiding its next-stage commands inside public iCloud calendar events.
- Microsoft fixed the September update that quietly stopped Windows File History from backing anything up.
- Gemini will now phone local businesses on your behalf, sit through the hold music, and hand you a transcript.
🔝 Top story: Washington wants first look at the newest AI models
The Office of the National Cyber Director asked OpenAI and Anthropic not to hand their newest frontier models to the UK's AI Security Institute until the US government has had a chance to test them first. The AI Security Institute is one of the best-resourced government model-testing labs anywhere, and until now it has generally received pre-release access so its researchers could probe new models for cybersecurity and misuse risks before the public got them. A senior administration official described the request as policy for new American frontier models, not a one-off.
Anthropic appears to have gone along with it, keeping Claude Mythos 5.1 inside a US-only partner set. OpenAI has not publicly said what it will do, and AISI director Henry de Zoete says the institute still has pre-release access to some frontier models, naming OpenAI's GPT-6 Astra. The subtext is not subtle: after a run of incidents where AI agents reached into systems they were not supposed to touch, including an Australian government health portal, frontier model access is starting to be handled less like product QA and more like export control.
In short: The White House has asked the two largest US AI labs to delay giving new frontier models to Britain's government safety testers until American reviewers go first.
What it means for your business: Nothing changes in your tenant this week, but the direction of travel matters. If model access is becoming a matter of national policy, expect more variation in which models are available in which countries, and build your AI workflows so swapping the underlying model is an afternoon of work rather than a rewrite.
My take: Independent pre-release testing is one of the few things in AI safety that actually produces evidence rather than press releases, so putting a queue in front of it is a real cost. Whether it is the right cost depends on things none of us can see. What I would not do is read this as the US turning against safety testing. It reads more like a country deciding that its most capable exports get inspected at home first. The thing worth watching is whether "US review first" comes with a clock on it, because a review with no deadline is just a veto with better manners.
Source: Reuters via Yahoo News
🤖 AI
Google's enterprise AI just grew a face
Google made Gemini 3.8 Live with Live Avatar generally available in Gemini Enterprise. It adds near-real-time generated video to Google's live dialogue model: a lip-synced talking face with natural expressions and turn-taking, speech to speech across 97 languages, and simultaneous vision and audio input. It runs through US and EU endpoints with provisioned throughput and enterprise data governance, and every generated audio and video stream carries an imperceptible SynthID watermark.
Companies pick from a library of pre-built avatars. Custom avatars built from a reference image are gated behind an enterprise allowlist and a verification process, which is Google quietly acknowledging that a "make a talking version of this face" button is a liability if you hand it to everyone.
In short: Google launched a real-time, lip-synced video avatar for Gemini Enterprise, generally available as of September 24.
What it means for your business: This is aimed squarely at customer service, onboarding and product walkthroughs. If you are considering it, the honest question is whether your customers want a face or want an answer. The watermarking matters more than the avatar does, because you are going to spend the next few years proving which videos of your brand are real.
My take: The technology is genuinely impressive and the use case is genuinely narrow. A synthetic face helps when the interaction is long, guided and instructional, like a walkthrough. It actively hurts when someone is frustrated and wants a resolution, where a face reads as a stalling tactic. My advice to anyone piloting this: measure resolution rate, not delight. And if you ever put a custom avatar of a real employee in front of customers, get that in writing from the employee first.
Source: Google Cloud Blog
The big three labs want to regulate themselves, formally
Google, OpenAI and Anthropic have agreed to set up an independent standards body for frontier AI, working name SAFA, the Standards Authority for Frontier AI. Reporting says it could launch late this year or in early 2027, and that the plan is narrower and more operational than the usual ethics-principles document: support for third-party safety testing before models ship, incident reporting rules, and qualification standards for auditors. The three companies have reportedly approached figures including former White House AI policy adviser Sriram Krishnan, former Biden technology official Arati Prabhakar, Condoleezza Rice and investor David Friedberg.
Because it would be a self-regulating organization, it would not need approval from Congress or the president to exist. That is the whole point, and also the whole objection.
In short: The three largest US AI labs are moving to create their own independent frontier-AI safety standards body, potentially launching by early 2027.
What it means for your business: If SAFA gets off the ground, its auditor standards and incident-reporting norms will eventually show up in your vendor questionnaires and your cyber insurance renewals. It is worth knowing the name now so you are not learning it from a form.
My take: Industry-written standards bodies have a mixed record. Sometimes they are how an industry gets its act together before regulators do it badly. Sometimes they are how an industry makes sure nobody does it at all. The tell will be the incident reporting: if SAFA requires labs to disclose incidents that embarrass them, on a clock, to someone who can publish, it is real. If reporting is voluntary and the definitions are written by the reporters, it is a logo.
Source: BankInfoSecurity
🛡️ IT and security
Seven forgotten accounts were all it took
Proofpoint published details of a Microsoft 365 password-spraying campaign it tracks as UNK_CondorFiltration, run with the open-source TeamFiltration toolkit. The numbers tell the whole story: 5,714 accounts targeted across 28 Microsoft 365 tenants, 32,825 authentication attempts from 1,487 AWS EC2 source addresses, spread over three waves from late July into August 2026, with the activity concentrated on Chilean retail and financial firms. One unnamed retailer absorbed 78.3% of all the observed authentication events.
Seven accounts fell. Every single one was an unmanaged functional or service account with no prior legitimate sign-in activity in Proofpoint's telemetry, carrying a default or never-rotated password and no MFA. Not one employee account was compromised. Once TeamFiltration gets a valid sign-in, it automates access to email, Teams, OneDrive, SharePoint and Microsoft Graph data.
In short: Attackers sprayed nearly 6,000 Microsoft 365 accounts and broke into seven, all of them unmanaged service accounts with default passwords and no MFA.
What it means for your business: Your employee accounts are probably fine. The scanner-to-email account, the old integration login, the shared mailbox nobody has signed into since 2023, the vendor account somebody set up during an implementation, those are the ones. Pull a list of every account in your tenant with no interactive sign-in in the last 90 days and no MFA registered, and work it top to bottom.
My take: This is the most useful security story of the week precisely because it is so unglamorous. The defenders did everything right on the human accounts. MFA held. Conditional access held. And then the attackers walked in through an account nobody owned, because the person who created it left the company and it never appeared on anyone's list. Service accounts are where security programs go to have blind spots. If you cannot name the human responsible for every non-human identity in your tenant, that inventory is your weekend project, and it is worth more than any tool you could buy.
Source: Proofpoint
A webmail flaw is being exploited, and no login is required
Attackers are actively exploiting CVE-2026-48842, a pre-authentication SQL injection vulnerability in Roundcube Webmail's virtuser_query plugin, carrying a CVSS score of 8.1. Canada's Cyber Centre flagged the exploitation in an advisory update, and BleepingComputer reported the activity on Wednesday. The flaw lets an attacker slip past the plugin's escaping with crafted backslash sequences and reach the database without authenticating at all. Fixed releases are 1.6.16 on the long-term support branch and 1.7.1 on the current branch, both shipped back in May.
Successful exploitation lets an attacker tamper with database operations and reach user identities, messages and address books.
In short: A pre-authentication SQL injection flaw in Roundcube Webmail, patched in May, is now under active attack.
What it means for your business: Most small businesses do not think they run Roundcube, and a surprising number do. It is the default webmail interface bundled with cPanel and many shared hosting plans, so if you have a website with hosting-provided email, ask your host what version they are running and when they patched. If you have a server somebody set up years ago and nobody has touched since, that is the one.
My take: "Pre-authentication" is the word that should make you move. There is no password to guess and no MFA to defeat. Anybody who can reach the login page can attack it. The patch has been available since May, which means four months of exposure for anyone who assumed their host was handling it. This is the standing argument for knowing who patches what: not because you will do it yourself, but so that when something like this lands you can send one email instead of starting an investigation.
Source: BleepingComputer
Mac malware is taking its orders from a shared calendar
Kaspersky researchers documented a significantly updated version of MacSync, a Swift-based macOS info-stealer that first appeared in April 2025. The new delivery trick is the interesting part: a downloader pulls commands out of the description field of a public iCloud calendar event, pipes them to zsh, and fetches the next-stage archive, with one of those stages hosted inside a public iCloud Calendar entry as an .ics file. Apple's own infrastructure becomes the command channel, which is a problem because no network filter is going to block iCloud.
The payload is a broad one. MacSync steals browser credentials, Keychain data, Telegram data and cryptocurrency assets, and a newly observed Objective-C backdoor module disguises itself as Finder, persists via LaunchAgent, .zshrc and Git hooks, runs attacker-supplied AppleScript, and can swap in a malicious browser extension or a fake Ledger wallet app. Distribution runs through ClickFix-style lures posing as Homebrew and macOS disk-space tools, plus cracked-software bait and a fake crypto wallet called Toria promoted on social media.
In short: An updated macOS info-stealer is using public iCloud calendar events as a command channel to deliver credential-stealing and backdoor payloads.
What it means for your business: The "Macs do not get malware" assumption keeps getting more expensive. If you have Mac users, they need endpoint protection and they need to know that a website telling them to paste a command into Terminal is always an attack, without exception. That ClickFix pattern is how most of this starts.
My take: Hiding commands inside iCloud calendar events is clever in the way that makes defenders tired. You cannot block iCloud on a fleet of Macs, so detection has to happen at the endpoint rather than the network, which means this is a tooling and training problem rather than a firewall problem. The specific thing to drill into your team: no legitimate software installation on a Mac ever involves copying a command from a web page into Terminal. Not Homebrew fixes, not driver updates, not "verify you are human." Ever.
Source: BleepingComputer
Windows quietly stopped backing up your files, and now there is a fix
Microsoft has fixed the bug that broke File History on Windows after this month's security updates. The problem arrived with KB5124008 on September 8: File History could fail to recognize an external or network drive, leaving scheduled backups stalled. It affected Windows 11 24H2 and 25H2 along with a range of Windows 10 and Windows 11 releases. Microsoft confirmed it earlier this week and shipped the fix in optional preview update KB5124010, with KB5124006 covering Windows 11 26H1.
The catch is that the fix lives in an optional update you have to install by hand. If you do nothing, it arrives with October's Patch Tuesday.
In short: A September Windows security update silently broke File History backups, and the fix is now available in an optional update.
What it means for your business: Anyone relying on File History as their backup has potentially had no working backup for over two weeks and received no warning. Check the last successful backup date on every machine that uses it, then either install the optional update or wait for October and verify afterward.
My take: The bug is a bug. The real story is that it failed silently for seventeen days, and the only reason most people will find out is that they read about it. That is the argument for a backup you actually monitor, with an alert when a job does not complete, rather than a feature you switched on once and trusted. File History was never meant to be a business backup strategy anyway. If it is yours, treat this as the nudge. And whatever you use, the only test that counts is restoring a file, not seeing a green checkmark.
Source: BleepingComputer
🧰 New tooling for builders and everyday AI use
Gemini will sit on hold so you do not have to
Google started previewing "Call for Me," a feature that has Gemini place calls to local businesses on your behalf. You tell it what you need, it dials, identifies itself as an AI calling for you, navigates the phone tree, waits on hold and talks to whoever picks up, while you watch a live transcript and can take over at any point. It handles things like checking whether an item is in stock, booking an appointment or changing a reservation.
The preview opened September 24 for Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL and Pixel 11 Pro Fold owners who have a paid Gemini subscription and are enrolled in the Phone by Google Public Beta.
In short: Google is testing a Gemini feature that calls local businesses for you, works through hold queues and phone menus, and shows you a live transcript.
What it means for your business: Two directions. As a caller, this is a real time saver for the errand calls nobody wants to make. As a business receiving calls, start thinking about what happens when a meaningful share of your inbound calls are AI agents acting for customers. Your phone tree, your hold policy and your staff's script all need to survive that.
My take: The consumer framing is the boring half. The interesting half is on the receiving end. If your front desk is the bottleneck in your customer experience, agents calling on behalf of customers will find that bottleneck faster and more persistently than humans ever did, because they do not get discouraged and hang up. Businesses that publish real availability and let people book online will get quieter phones. Businesses that hide behind a phone tree will get a queue of tireless robots. I would not panic about this, but I would stop treating "call us" as a customer-friendly answer.
Source: TechCrunch
Yesterday's edition is here if you missed it: AI and IT News Recap: September 24, 2026.