An OpenAI agent accessed non-public parts of an Australian government website while trying to answer a research question, and OpenAI took three months to tell anyone. A hacking group claims it stole data on every FBI employee and applicant through a jobs portal. And Anthropic and OpenAI released cheaper models 90 minutes apart: Claude Opus 5.5, and GPT-6 Sol and Luna.
An OpenAI agent broke into non-public parts of an Australian government website during testing, and OpenAI took three months to tell officials. Ashley's take: give AI agents the least access possible, log what they do, and ask vendors how fast they disclose problems. A hacking group claims it stole data on every FBI employee and applicant through a jobs portal. Her take: your HR, payroll, and applicant tracking vendors are your weak spot, so check them this week and train your team to spot scam calls. Then Anthropic's Claude Opus 5.5 lands 40% cheaper, and 90 minutes later OpenAI's GPT-6 Sol and Luna arrive at half the price of the last generation. Her take: the price war favors you, so skip locked-in contracts and match the model to the job. AI news you should know about, in under 10 minutes.
In this episode:
(00:11) Intro: this week's headlines on a rogue OpenAI agent, the FBI data breach claim, Claude Opus 5.5, and GPT-6 Sol and Luna
(00:42) A quick word from our sponsors
(00:49) Let's dive in: rogue OpenAI agent accesses an Australian government website
(01:38) How it happened: an AI crawler finds a security workaround
(02:02) The link to last episode's hidden notes story
(02:13) Three months to disclose, and Albanese's response
(02:31) Not the only case: Transluce's findings and the forensic investigation
(02:57) Ashley's take: least access, activity logs, and human approval
(03:33) Ashley's take: ask your AI vendor how fast they'll disclose problems
(03:55) ShinyHunters claims data on all FBI employees and applicants
(04:23) Where the data came from and how much is verified
(04:46) The FBI's response
(05:01) How they got in: a zero-day in Oracle PeopleSoft, and the revenge motive
(05:33) Why it's scary, and the group's track record
(06:12) Ashley's take: your HR and payroll vendors are the weak spot
(06:46) Train your team for follow-up scam calls, then a quick break
(07:21) Claude Opus 5.5 is here and 40% cheaper
(07:42) The price breakdown, speed, and higher usage limits
(08:26) Real-world results and fewer invented figures
(08:54) Availability, and Ashley's take: push the workflows you've been rationing
(09:40) OpenAI launches GPT-6 Sol and Luna, 90 minutes later
(10:09) Sol vs. Luna, and half the price of the 5.6 series
(10:31) The "fewer mistakes" claim and availability
(10:59) Ashley's take: the price war favors you, so avoid lock-in
(11:10) Match the model to the job
(11:31) Progress, not permission to stop checking
Links:
Follow Ashley at @ashleyrcoffey89 on Instagram and Threads. Want the highlights without the twice-a-week commitment? Ashley's monthly newsletter is linked in her bio. Send us a topic you want covered, and follow the show for AI news you should know about.
Ashley Coffey (00:11)
There's a lot of AI news out there, but we give you the weekly highlights very quickly. This week on the show, we'll be talking about Rogue OpenAI agent infiltrated Australian government website and world first. A high-profile hacking group claims it breached multiple FBI-related services and stolen data on, quote, all FBI employees and applicants.
Ashley Coffey (00:32)
Claude Opus 5.5 is here and it's 40% cheaper. and OpenAI launches GPT-6 Soul and Luna, boasting lower cost and fewer mistakes.
Ashley Coffey (00:42)
We'll be covering all of that on our show today, but first, here's a quick word from our sponsors.
Ashley Coffey (00:49)
Welcome back. Let's dive in. Rogue OpenAI Agent infiltrated Australian government website in a first. This is coming from BBC. I'll link the article in the show notes. Let's talk about it. Australian Prime Minister Anthony Albanese announced that OpenAI agents successfully accessed non-public parts of a government Medicare statistics portal on June 18th, 2026.
Ashley Coffey (01:11)
Medicare is Australia's national health insurance program. What was in there? The agent accessed both public and non-public files, but the portal holds non-sensitive Medicare information relating to data and statistics such as spending. OpenAI said its review found that no evidence that patient records were accessed. How it happened though, OpenAI says an agent hacked Australian government website without being told to do so.
Ashley Coffey (01:38)
OpenAI said the activity occurred during an internal evaluation as its models attempted to look up answers and statistics about Australia, and in OpenAI's words, the models quote, took actions we did not intend. Reporting indicates an AI crawler, an automated program that scans websites and collects information, found a security workaround to get the data.
Ashley Coffey (02:02)
Call back to our last episode. OpenAI discovered this during the review of misaligned behavior disclosed last week. The same review behind the quote hidden notes story we covered.
Ashley Coffey (02:13)
The timeline is the part that's making people angry, though. The breach happened in June of this year, and OpenAI only became aware of it in August and informed Australian officials on 10th of September by email. Albanese said that he told Sam Altman, quote, It took the company way too long to inform the government on what had occurred.
Ashley Coffey (02:31)
And it may not be the only case. AI research lab Transluce said it had detected AI agents going rogue on several occasions, going back to at least March, with targets including a University of New Mexico library.
Ashley Coffey (02:44)
And the website of Australian Institute of Health and Welfare, though none of those attempts were successful. Australia's cybersecurity agency, the Australian Signals Directorate, is leading a forensic investigation.
Ashley Coffey (02:57)
My take here, this is the first headline where AI agent and unauthorized access show up in the same sentence for real. And it happened while the agent was just trying to answer a research question. That's the part that we should really set with. the agent was not malicious, it was determined.
Ashley Coffey (03:15)
If you're piloting agents that browse the web, log into tools, or act on your behalf, give them the least amount of access possible, keep a log of what they do, and have a human approve anything that touches money, customer data, or outside systems. The other lesson here is about disclosure.
Ashley Coffey (03:33)
Three months to tell a national government is a trust problem. When you pick an AI vendor, ask how and how fast they'll tell you if their product does something to your data it shouldn't have. All right, next. A high-profile hacking group claims it has breached multiple FBI-related services and stolen data on quote, all FBI employees and applicants.
Ashley Coffey (03:55)
This is coming out of 404 media. Let's talk about it. The group called Shiny Hunters, and they told 404 Media that they quote, hacked the FBI and they hold all data on FBI employees and applicants.
Ashley Coffey (04:07)
What they claim to have is between two to three terabytes of data, plus a sample appearing to contain information on 5,000 FBI employees, including alleged home addresses, phone numbers, dates of birth, and in some cases, spousal information.
Ashley Coffey (04:23)
The group says the data comes from several FBI services, including HR, a medical database called Medlink, and FBI Jobs Portal. Is it real? Partly verified so far, in at least nine cases, Reuters found that the details appeared to match but couldn't establish where the data came from or whether it held had been stolen from the FBI's internal systems, as the hackers have claimed.
Ashley Coffey (04:46)
The FBI's response here, it's aware of a group claiming a compromise of FBI jobs.gov portal, says the point of breach is still undetermined whether a third party or the FBI itself and is working with third-party providers to support that site.
Ashley Coffey (05:01)
How they got in, Shidy Hunters told Cyber News the breach followed its apparent discovery of a zero-day vulnerability in Oracle's PeopleSoft Enterprise software. Quick definition: a zero-day is a security hole the software maker doesn't know about yet, so there's no fix available. Why they did it? It's revenge.
Ashley Coffey (05:20)
The group said it targeted the FBI in response to a May 2026 agency announcement that detailed Shiny Hunter's methods and advised targets not to pay. The group has said the attack isn't financially motivated.
Ashley Coffey (05:33)
Why it's scary here, criminals from the same ecosystem have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. And a major concern here is whether Shiny Hunters chooses to sell the data to other criminal or nation-state hackers.
Ashley Coffey (05:50)
The bonus wow here. This is the same group behind the purported theft of millions of business records from Rockstar Games, the maker of Grand Theft Auto, and a May intrusion centered on education tool, Canvas, that caused widespread disruption across schools. And earlier this month, Anthropic cited had caught Shiny Hunter's linked hackers trying to use its tools.
Ashley Coffey (06:12)
My take here, if the FBI can get hit through a jobs portal, your business and anything else you have connected to your AI tools can get hit through your HR software, your applicant tracking system, or your payroll vendor. The most sensitive data most businesses hold isn't customer data, it's employee data, addresses, birthdays, social security numbers, emergency contacts.
Ashley Coffey (06:35)
In this week, ask two questions. Which outside vendors hold your employee and applicant data and are they patching quickly? Your security is only as strong as your weakest vendor.
Ashley Coffey (06:46)
And don't forget to train your team for follow-up attacks here. Stolen personal info fuels convincing scam calls and texts that target employees and their families. A quick 15-minute here's what a fake IT call or a bank call sounds like is the cheapest security investment you can make. All right, we're gonna take a quick break, but when we come back, we'll be talking about Claude Opus 5.5 is here and it's 40% cheaper.
Ashley Coffey (07:11)
OpenAI launches GPT Six Soul and Luna, boasting lower costs and fewer mistakes.
Ashley Coffey (07:21)
Welcome back, continuing with our stories. Alright, Claude Opus 5.5 is here and it's 40% cheaper. This is coming directly from Anthropic. Let's talk about it. Anthropic released Claude Opus 5.5 on September 22nd. It performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.
Ashley Coffey (07:42)
The price breakdown. Input and output are $4.20 per million tokens, 20% less than Opus V and cache Reads, which make up the majority of agentic encoding costs are 20 cents per million tokens, which are 60% less. Tokens are the chunks of text AI models are built by, roughly three-quarters of a word each. It also generates output more than 30% faster for subscribers. Anthropic is increasing five.
Ashley Coffey (08:09)
Hour usage limits on Pro, Max, Team, and Seat-based enterprise plans, and giving subscribers a rate limit reset they can save and use whenever they choose. When testers found its writing clearer and easier to follow, most important information came faster up front.
Ashley Coffey (08:26)
A real-world example here at a company called Quantum, a complex coding task that previously took 38 prompts over four days came in at 11 prompts over three hours.
Ashley Coffey (08:36)
And a nice counterpoint to the last episode's made-up data story in a research test where any invented figure or quote meant failing. 16 out of 18 of Opus 5.5 reports cleared the quality bar, while neither Fable 5.1 nor Opus 5 cleared it in any attempt.
Ashley Coffey (08:54)
Availability. It's available on all platforms, including Amazon Web Services, Google Cloud, and Microsoft Azure, and Cloud Sonnet 5.5 and Haiku 5.5 will follow in the coming weeks. My take here if your team was on Cloud Team or an Enterprise Pan, you just got more usage for the same price. That's a free upgrade, so it's a good week to push the workflows you'd been rationing. The 40% cost drop matters if you're building automations on top of Claude. Same work, lower bill is how.
Ashley Coffey (09:22)
how
Ashley Coffey (09:22)
a pilot turns into something you can actually roll out across the team. The writing improvement is underrated here. Most of what my clients use AI for is client facing, so things like emails, proposals, reports. Output that needs fewer edits is real time saved. Still spot check the numbers, but fewer invented figures is exactly the direction that we want.
Ashley Coffey (09:40)
Next up, OpenAI launches GPT Six Soul and Luna, boasting lower costs and fewer mistakes.
Ashley Coffey (09:47)
Almost 90 minutes after Anthropic had their announcement, OpenAI launched GPT-6. The timing is wild. And OpenAI's release reflects the intense competition between the two companies. What they are, earlier this month, OpenAI launched GPT-6 Astra, it's the most powerful model yet, and is now expanding the GPT-6 generation with updated versions of the smaller Sol and Luna models.
Ashley Coffey (10:09)
Who does what? Sol is designed for complex tasks like coding, while Luna is meant for high-volume tasks with a clear goal, like summarizing documents, extracting information, or answering quick questions. the price, the six series models will be available at half the cost of the 5.6 series in the API, which OpenAI attributes to improvements in caching and inference.
Ashley Coffey (10:31)
The fewer mistakes claim on OpenAI's internal evaluation, based on real conversations where users flag mistakes, GPT-6 Soul makes about half as many mistakes as its predecessor, reaching Astra level reliability at much lower cost. It's worth noting here that predecessor GPT 5.6 Soul is the model family from last episode's hidden note story. Availability: the Soul and Luna are available in ChatGPT Work and Codex for most paid accounts and in the API, while Luna
Ashley Coffey (10:59)
Will also be available for free and Go users. My take two major labs cutting prices within 90 minutes of each other is the best news in this episode for most business owners.
Ashley Coffey (11:10)
The price war is working in your favor, so this is not the moment to be signing a long locked-in contract with any particular AI vendor. The Sol versus Luna split is the lesson worth stealing. Match the model to the job. Summarizing invoices or pulling data from forms doesn't need the most powerful model. Using the lighter tier for routine high-volume work is one of the easiest ways to cut your AI bill.
Ashley Coffey (11:31)
Half as many mistakes still means mistakes, though. It's progress, not permission to stop checking, especially on anything with numbers, contracts, or compliance attached. That's it for AI News That You Should Know About for this week. Show notes have a link to everything we have covered. If you want more of this, that's what our socials are for. You can find me on Instagram and Threads at AshleyRCoffey89.. Follow the show, send us a topic you want covered, and we'll see you next week for more AI news that you should know about. Thanks for listening.