SecuFocus

Announcements · News

What just
shipped.

Each note starts from the publisher’s page. It says what changes for your data, and what we did not verify.

The announcements

17 announcements
FlawBriefAnnouncements

Microsoft: an Exchange flaw can read other mailboxes, if you are already signed in

On 2 October 2026, Microsoft publishes early security updates. One CVE: CVE-2026-96940, Exchange Server, base score 8.8, severity Important. An already authenticated attacker can read other mailboxes in the same organization. Microsoft says the flaw is not exploited, and that Exchange Online is already fixed on the service side.

AIBriefAnnouncements

Google: Gemini 4 Argon is not open to the public

On 30 September 2026, Google announces Gemini 4 Argon. This is not a button in the Gemini app. The model goes first to trusted cyber defenders, in a program named Fairwind. The public, developers and enterprises wait.

AIBriefAnnouncements

OpenAI: GPT-6.1 Sol is in Work, not in Chat yet

OpenAI presents GPT-6.1 Sol as a more capable Sol, close to Astra on some work, at one fifth of Astra’s listed price. It is in ChatGPT Work and Codex. It is not in Chat yet.

AIBriefAnnouncements

OpenAI: dots keep working, on a computer that is not yours

On 29 September 2026, OpenAI presents dots: agents that stay on, powered by GPT-6 Astra, with their own computer in the cloud. The page says you remain in control. It also says they work while you are away.

FlawBriefAnnouncements

Firefox 157 fixes high-impact flaws, including sandbox escapes

On 29 September 2026, Mozilla publishes MFSA 2026-97 for Firefox 157. The stated impact is high. The advisory names sandbox escapes and use-after-free bugs. It does not say these flaws are being exploited.

AIBriefAnnouncements

Anthropic: Sonnet 5.5 is faster, and still at Claude

On 28 September 2026, Anthropic announces Claude Sonnet 5.5. At least 30 percent faster than Sonnet 5, up to 30 percent cheaper for most work, at the same listed price: 2 dollars per million input tokens, 10 output. The model is not at your place.

AIBriefAnnouncements

xAI: a Team Bot shares files, memory and access with the whole team

On 28 September 2026, xAI launches Team Bots. A role bot receives the files, applications and credentials the work needs, then it is shared. Everyone works from the same context. Memory keeps what it learns.

TechBriefAnnouncements

Apple ships iOS 27.0.1 with no published CVE

On 28 September 2026, Apple lists iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1. The security releases page says these updates have no published CVE entries.

AttackBriefAnnouncements

CISA: two Citrix NetScaler flaws are being exploited, and each can run remote code

On 27 September 2026, CISA amplifies eight Citrix NetScaler ADC and Gateway flaws. Two of them, CVE-2026-88771 and CVE-2026-88772, are in the known exploited catalog. CISA says each can enable remote code execution, and that actors are exploiting them. Update on 2 October: a SIGMA rule.

AIBriefAnnouncements

OpenAI: ChatGPT ads spread, the conversation stays the product

On 23 September 2026, OpenAI extends ChatGPT Ads to Indonesia, Malaysia, the Philippines, Singapore, Thailand, Vietnam and Taiwan. The page says conversations stay private from advertisers, and that ads do not change the answers. That is OpenAI’s promise, not a measurement.

AIBriefAnnouncements

OpenAI: GPT-6 Sol and Luna cut the API price, not the recipient

OpenAI adds GPT-6 Sol and GPT-6 Luna under Astra. The Sol API goes from 4 to 2 dollars per million input tokens, and from 20 to 10 output, against GPT-5.6 promotional pricing. Luna drops to 0.10 and 0.50. The text still leaves for OpenAI.

AIBriefAnnouncements

Anthropic: Opus 5.5 costs less per token, and keeps the high-end guardrails

On 22 September 2026, Anthropic announces Claude Opus 5.5. The listed price is 4 dollars per million input tokens and 20 output, 20 percent less than Opus 5. Cache reads are 0.20, announced 60 percent lower. On biology and cyber, the page says guardrails close to those of Mythos.

AIBriefAnnouncements

xAI: Grok 4.7 keeps the 4.6 price, and opens a cyber door by invitation

On 21 September 2026, xAI announces Grok 4.7. The banner says a model twice as fast and half the price of comparable models. The body says it is served at the same price and speed as Grok 4.6. Those two sentences do not say the same thing.

AIBriefAnnouncements

xAI: Grok Voice Transcribe 2.0 takes the audio, priced by the hour

On 18 September 2026, xAI releases Grok Voice Transcribe 2.0. The page calls it twice as accurate as version 1.0, at the same price: 0.10 dollar per hour in batch, 0.20 streaming. The audio leaves for xAI. The accuracy is their measurement.

AIBriefAnnouncements

Anthropic: a program opens biology tasks that public models block

On 17 September 2026, Anthropic opens applications for the Life Sciences Verification Program. Verified teams get Mythos, Opus and Sonnet with safeguards that are more permissive for biology work. Public Fable models still block those tasks.

AIBriefAnnouncements

Nous: Hermes Agent 0.21 puts bots that talk to each other in the app

On 31 August 2026, Nous publishes Hermes Agent 0.21.0. Bot Mode enters the desktop app, on by default: named agents, rooms, and the hermes peer command so one agent can write to another. Scheduled tasks keep a memory. The agent can drive the desktop browser.

AIBriefAnnouncements

Anthropic: future Claude models will carry an invisible watermark, with no name

On 14 August 2026, Anthropic explains that future Claude models will mark their text. The watermark would not add hidden characters, would not cost more, and would not, according to the page, carry a way back to a person, an organization or a chat.