This Week: Patch Now or Pay

⚠️ Some links on this site are affiliate links. If you buy through them, we earn a small commission at no extra cost to you. This never influences our reviews.

Welcome back to the itpick weekly news roundup — your no-nonsense guide to what’s actually worth knowing in the world of IT this week. It’s been a busy one, with some genuinely alarming security stories sitting alongside a fairly massive moment in AI history. Let’s get into it.

Someone Broke Into Hotel Rooms to Hack Executives’ Laptops

This one reads like a spy thriller, but it’s completely real. A Chinese state-linked hacking group — tracked by security firm CrowdStrike as OVERCAST PANDA — targeted executives attending an agricultural industry conference in China earlier this year. While attendees were out at dinner, operatives reportedly entered their hotel rooms, physically booted their laptops from a USB stick, and installed backdoor software. No phishing email, no dodgy link — just old-fashioned breaking and entering with a high-tech twist.

The particularly frustrating bit? A fix existed that would have blocked this kind of attack, but many of the affected companies simply hadn’t applied it. It’s a reminder that keeping firmware settings locked down and enabling Secure Boot isn’t just nerdy IT box-ticking — it can genuinely stop attackers in their tracks.

What this means for you: If you travel for work, never leave your laptop unattended in a hotel room without enabling a BIOS password and full-disk encryption — and make sure your operating system is fully up to date before you go anywhere.

Microsoft Patches Nearly 400 Security Vulnerabilities

This month’s Patch Tuesday was, to put it mildly, a big one. Microsoft pushed out fixes for close to 400 security flaws across Windows and its wider software ecosystem. One of those vulnerabilities was already being actively exploited in the wild before the patch dropped, and two others had been publicly documented — meaning attackers had a head start.

Four hundred vulnerabilities in a single update cycle is a lot, even by Microsoft’s standards. The actively exploited flaw is the one to prioritise: if attackers are already using it, every day you delay is a day of unnecessary risk.

What this means for you: Open Windows Update right now and make sure everything is installed. Seriously — don’t put it off until the weekend. This is one of those months where procrastinating could genuinely cost you.

A Sneaky Piece of Malware Turns Off Windows Defender — Then Mines Crypto

Researchers at Elastic Security Labs have shed light on a nasty piece of kit called REVSTEALER — an information stealer that sneaks onto Windows machines, nicks whatever data it can find, and then quietly deletes itself. Job done, you’d think. But it leaves four hidden programs behind, and one of them turns off both Windows Update and Microsoft Defender before firing up a cryptocurrency miner using your hardware and electricity bill.

It’s a double punch: your data gets stolen, and then your PC gets conscripted into someone else’s money-making operation, all while your defences are quietly switched off in the background. This is exactly the kind of threat that a layered security approach is designed to catch — meaning you shouldn’t rely solely on Windows Defender. A dedicated security solution adds a meaningful extra layer, particularly for small businesses running Windows machines day in, day out.

What this means for you: Make sure you have active, up-to-date security software running beyond just Windows’ built-in tools, and consider a password manager like NordPass to limit the damage if credentials are ever lifted without your knowledge.

OpenAI Says We’ve Reached AGI — Meet GPT-6 Astra

It’s the announcement the AI world has been building towards for years. OpenAI has launched GPT-6 Astra, and the company is billing it as the arrival of artificial general intelligence — meaning a system capable of outperforming humans across most economically valuable tasks. That’s an enormous claim, and the tech community will be stress-testing it heavily in the weeks ahead. For everyday users and small businesses, the practical question is what this means for AI-powered tools you already use day-to-day — whether that’s writing assistants like Grammarly, AI note-taking in Notion, or the AI features baked into productivity apps across the board. Expect those to get considerably more capable in the coming months as this technology filters down.

What this means for you: You don’t need to do anything today, but it’s worth paying attention — the AI tools you use for work are likely to improve significantly in the near future.


That’s your week in IT. The big takeaway this time around is frankly just: patch your stuff. Between nearly 400 Windows vulnerabilities, malware that disables your defences, and physical attacks exploiting unpatched firmware, the theme is consistent — updates exist for a reason, and ignoring them is genuinely risky. Stay safe out there, and we’ll see you next week.

security Windows AI malware patch Tuesday