Summary
A string of break-ins at South Korean banks shows what AI tools already do for an ordinary attacker: they make familiar tricks faster and easier to repeat, not magical. The rest of the week points the same way, from cheap new AI models built to make yes-or-no calls to a scientist catching errors his AI reviewers missed. The edge goes to businesses that check, log and limit what their software does.
Highlights
Korean bank attackers used AI tools, but got in through side doors like loan-broker portals, not core systems.
Every login-protected page on your site needs its own check, not just the front door.
Microsoft, OpenAI and Liquid AI all shipped cheap AI models that return a probability, not a paragraph.
Use decision models for sorting and routing, and test them on your own data first.
Only 3.6% of Chinese AI model releases came with published safety results, SemiAnalysis found.
Medicare's AI app plans were shaped in a private chat room dominated by tech companies.
88% of CIOs say AI use is moving faster than their rules for it.
An astrophysicist caught errors that two rounds of AI review missed; keep a person on final checks.
Judge robot vendors on time between interventions and cost per task, not demo videos.
Quick Takes
Anthropic's free bug scanner shows its numbers. Anthropic's OSS Scanner, which runs its strongest Claude models over open-source projects that sign up, has found more than 29,000 candidate vulnerabilities in major software. A little over 6,000 have gone to maintainers, producing 584 security advisories as of October 2, and 116 projects had applied to join. The reports are fully machine-written with no human triage first, so expect some false alarms. If your business runs on open-source software, watch those projects' security notices. Read more
USA Today's owner sues OpenAI. USA Today Co. and several of its papers, including The Tennessean, IndyStar, The Columbus Dispatch and The Oklahoman, sued OpenAI on October 8 for more than $250 million, alleging it copied "hundreds of thousands of articles for AI training without authorization." The claims have not been tested in court. The suit joins cases from The New York Times, Ziff Davis, Encyclopaedia Britannica and others, and keeps the question of who pays for training data open. Read more
What's Covered in Featured News
AI tools in the Korean bank break-ins: what CrowdStrike found, how the attackers got in, and why the tool's maker shut it down.
Models that decide instead of write: Microsoft's Decision-1, OpenAI's Decisions API and Liquid AI's open d1 models.
Medicare's AI policy chat room: how a government Slack workspace gave tech firms a direct line to health officials.
China's missing safety reports: SemiAnalysis counts how rarely Chinese labs publish safety test results.
CIOs say AI is outrunning the rules: a 3,200-person survey on who owns AI governance.
AI does science, people check it: a full ultraviolet map of the sky and a fast Ebola risk map, and what the humans caught.
Physical AI: why "boring" robots may win, Jabil on building humanoids at scale, Helm.ai's $70 million in contracts and New York's AI companion program for older adults.
Featured News
AI tools helped one attacker hit Korean banks through side doors
A string of break-ins at South Korean lenders has become the clearest real-world case yet of an attacker leaning on AI tools, and the details are more useful than the headlines. On October 7, CrowdStrike released a report on attacks between late September and early October. It said the person behind them is "likely a Chinese speaker and financially motivated," an assessment made "with moderate confidence," and not tied to any known hacking group. The attacker ran ARTEX, an open-source penetration-testing agent built in China, mainly on DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 also used through Claude Code sessions. CrowdStrike found two servers, one in Hong Kong serving as main infrastructure and another hosting ARTEX. In one Claude Code session, the attacker asked Claude to draft a security researcher résumé listing an age of 26 and a degree from South China University of Technology, and elsewhere asked about marketplaces and Telegram groups that sell stolen Korean data. The attacker's identity is not confirmed.
At least nine South Korean banks have disclosed attacks or been named by local media since late September. The systems hit were not core banking. One was a loan inquiry service used by outside brokers; at Shinhan Bank, a Cloud Security Alliance research note says, that service exposed names, phone numbers, annual income and borrowing limits for about 25,000 customers. Another was an employee mobile work app. Press totals across seven lenders run from roughly 60,000 to 68,000 records, and no regulator has published a combined count. How the attacker got in is still disputed: one account describes skipping a login check and cycling through customer ID numbers, another describes reusing passwords leaked in earlier breaches.
On October 8 the ARTEX developer, known on GitHub as Autumn-27, wrote that "given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source," and the project page came down. South Korea's Financial Supervisory Service told banks to focus less on who is connecting and more on how requests arrive, since blocking addresses is not enough. China's foreign ministry said it was not familiar with the case.
The sober reading comes from the Cloud Security Alliance, which says "no evidence yet shows the tool did anything a skilled attacker with conventional scanners could not." That is the business lesson. AI did not invent a new attack; it helped one person organize and repeat old ones at scale. The weak points were partner portals and staff apps that sit outside the main login, which describes plenty of small businesses too.
Models that decide instead of write
In the same week Jev's maker was valued at $7.5 billion, the biggest names moved into the same niche: AI models that return a score instead of text. Microsoft launched Microsoft-Decision-1 in its Foundry platform on October 9. It is a version of Alibaba's open Qwen3.5-9B model retrained to look at a fixed set of options, such as yes or no, a multiple choice or a rating, and return a probability for each. It can also grade another AI's answers or an agent's actions against a rubric. Microsoft prices it from 4.2 cents per million units of input text, with output free, and says it runs 35 times faster than GPT-6 Sol. Xbox Research used it to label more than 10,000 feedback items. OpenAI opened a public test of its Decisions API on October 6, running only on gpt-6-luna, with three answer types: whether a statement holds, which option to pick and a score on a scale. It charges $0.10 per million input units with no charge for output, claims answers up to 10 times faster than the same model through its regular API, and expects full release "in the coming weeks." Liquid AI released two small open models, d1-3B and d1-omni-600M, on Hugging Face so companies can run this kind of decision on their own machines; the smaller one also takes audio.
All of the speed and accuracy figures come from the vendors. The use case is plain, though: sorting tickets, flagging invoices, routing leads and checking an agent's work are yes-or-no jobs, and they just got much cheaper.
Tech firms shaped Medicare's AI plans in a government chat room
A KFF Health News investigation by Amanda Seitz, Maia Rosenfeld and Darius Tahir, published October 9 with CBS News, describes a Slack workspace the Centers for Medicare & Medicaid Services started in August 2025. It has grown to about 1,700 members, mostly AI firms, digital health startups and investors, with only a handful of patient advocates, doctors and hospital representatives. Jacob Shiff of the CMS Innovation Center described the agency's work as a potential "sales engine" for health apps. CMS's Medicare App Library promotes about two dozen commercial apps, and in September CMS launched a program letting health apps bill Medicare for AI services such as wearable tracking; officials suggested apps in the library would get priority. Former FDA lawyer Joseph Daval said the room in some ways resembles a federal advisory committee, which would normally have to meet in public. CMS declined to say whether the workspace is legal. Chief product officer Amy Gleason called it "an open, voluntary technical collaboration." For health and wellness businesses, the takeaway is that the rules for getting paid for AI care are being set now, and so far by a narrow group.
China's AI labs rarely publish safety tests
SemiAnalysis analysts Mark Chen, Doug and Dylan Patel built a dataset of 857 AI model releases from nine Chinese developers between 2021 and September 15, 2026. Only 31, or 3.6%, have ever had a published safety result, and only 9, or 1.1%, had one at or before launch. Another 16 published results only after release, a median 42 days later, and 813 releases, 94.9%, have no safety disclosure at all. The authors argue Beijing's approach is "speed-first," regulating content and apps rather than the most capable models. A missing report is not proof no testing happened. But these cheap open models are increasingly the default inside business tools, and one of them powered the Korean bank attacks, so ask any vendor which model sits underneath and what testing it can show.
CIOs say AI is outrunning their rules
Thoughtworks surveyed 3,200 chief information officers in 10 countries, and 88% said AI adoption in their organization is moving faster than their governance can adapt. Nine in 10 expect central IT to be blamed for AI-related breaches or compliance failures, and 89% say they are now more responsible for redesigning workflows and jobs than for core infrastructure. Seventy percent of organizations have hired a chief AI officer and 26% plan to. "AI governance is also a workforce design issue," said Thoughtworks CTO Rachel Laycock. A small business has no CIO, but the same gap applies: tools arrive faster than anyone decides who may use them for what.
AI does science, and people catch what it missed
Brice Ménard, a Johns Hopkins astrophysicist who is also a researcher at Anthropic, used Claude Science to build what Anthropic calls the first complete ultraviolet map of the sky, merging data from NASA's GALEX and other surveys. About a third of the map is predicted rather than measured, and on regions where real data was hidden as a test, Claude's estimates came within about 10%, a self-reported result. The telling detail: Ménard spotted faint circular smudges from leftover atmospheric glow that two rounds of AI agent review had missed, and Claude then corrected all 38,000 observations. Separately, Google said the World Health Organization's Africa office used its Earth AI tools during the Ebola outbreak in Congo to identify 48 exposed settlements and more than 45,500 at-risk people within minutes, work that normally takes weeks. Both are real speedups, and both are vendor accounts. The pattern holds: AI does the heavy lifting, and an expert still signs off.
Physical AI
The case for unglamorous robots got a strong push this week. In a Robot Report column, Ron Zukerman of sensor maker Vishay Precision Group argues the industry too often builds a robot and then hunts for work, when it should start from a paying task and work backward. In a new plant, he writes, a specialized machine usually beats a humanoid; in an old building designed for people, legs and two arms can earn their place. He says repeat purchase orders, not viral videos, prove value, and proposes four numbers to judge any robot: mean time between interventions, cost per unit of work, time to redeploy it and safety incidents per operating hour. His own example, from his company's tests, is that tighter force control on connector assembly cut scrap from 1.2% to 0.5%, which he estimates saves about $450,000 a year per line. He sells sensors, so weigh the pitch, but the four metrics are worth putting in any robot quote.
Building humanoids at volume is its own problem. Thomas Brown, a senior engineering director at contract manufacturer Jabil, told The Robot Report that most customers still build humanoids in low numbers and the industry is only moving toward tens of thousands of units. He called component prices "an ongoing pain point for scale," flagged wiring harnesses that need car-grade toughness in a tiny space, and said supply chains are being reset and diversified. Asked when humanoids reach homes, he said: "Maybe in five-ish years. It could be 20 years." Jabil has worked with Apptronik to put its Apollo humanoid into active manufacturing settings.
Software for machines that move is starting to pay its way. Helm.ai, a Redwood City company that trains AI models for self-driving and industrial machines, said it has signed about $70 million in commercial contracts over 12 months with carmakers, auto suppliers and industrial automation firms, with projects heading into production in vehicles, mining and construction. CEO Vladislav Voroninski said the company is "on a path to break even, which is rare in this space," and that robotics today is "almost where autonomous driving was 10 years ago."
The most deployed robot in this week's news is a tabletop companion. New York State's Office for the Aging extended its program giving older adults ElliQ, a talking AI companion from Intuition Robotics, after three years of tracked results. Hundreds of people have received one since 2022 and more than 3,500 applied in 2025 alone. In 2026 data, 94% of participants reported feeling less lonely and users averaged 48 interactions a day. Those are self-reported survey results and the state did not disclose the cost, but it is a rare public program measuring a home robot over years rather than weeks.
What This Means for Your Business
Audit your side doors this week. The Korean attacks did not break into core banking; they went through a broker portal and a staff app. List every page or app that touches customer data: client portals, vendor logins, booking tools, the old intake form your web developer built. Confirm each one checks who is asking on every request, not just at the login page, that partners and staff use two-factor login, and that someone gets an alert when one account looks up hundreds of records in a row. AI makes it cheap for one person to try those doors all night.
Try a decision model on one boring, high-volume call. If you route support tickets, flag unusual invoices, score leads or check whether an AI draft follows your rules, the new Microsoft and OpenAI decision services cost a fraction of a chatbot and answer much faster. Start with a few hundred past examples where you know the right answer, measure how often the model agrees, and set a threshold below which a person decides. Do not trust a vendor's calibration claims until you have checked them on your own data.
Know which model is inside your tools. Many inexpensive AI products now run on Chinese open models, and SemiAnalysis found almost none publish safety tests. That is not a reason to ban them, but it is a reason to ask vendors what model they use, where your data is processed and what testing they can show, especially for anything touching customer records or payments.
Write down your AI rules before the tools outrun them. The CIO survey is a big-company result, but the gap is the same in a 20-person firm. A one-page policy covering which tools are approved, what data may never go into them and who reviews AI output before it reaches a customer closes most of it.
Keep a human on the last check. A world-class scientist found errors two rounds of AI review missed. Let AI draft, sort and calculate, but make one named person responsible for anything that goes out the door.
Sources
Chinese-speaking hacker possibly behind attack on Korean banks, CrowdStrike says — Korea JoongAng Daily
Shinhan Bank Breach: Suspected AI-Agent Intrusion via Loan Portals — Cloud Security Alliance
Chinese developer makes ARTEX AI agent closed-source after Korean bank hack — The Standard
Microsoft launches Decision-1 model in Foundry — TestingCatalog
OpenAI Opens Decisions API Public Beta — Let's Data Science
Liquid AI releases open d1 models for multimodal edge decisions — Runtime Wire
AI, Tech Leaders Are Lobbying Trump Health Officials in a Government-Run Chat Room — KFF Health News
Beijing Will Not Pace the Frontier: China's Speed-First AI Safety Regime — SemiAnalysis
CIOs shoulder AI workforce redesign as governance lags — IT Brief UK
The missing map of the sky — Anthropic
Making global public health more proactive with Google Earth AI — Google
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects — The Hacker News
USA Today sues OpenAI, seeking more than $250 million — Crypto Briefing
Will 'boring' robots win in the real world? Why robotic form should follow workflow — The Robot Report
Jabil discusses the pace of humanoid robot development and production — The Robot Report
Helm.ai reaches $70M in signed commercial contracts for its foundation models — The Robot Report
New York extends AI companion program in partnership with Intuition Robotics — Robotics & Automation News