This Week: AI & Big Threats
Welcome back to the itpick weekly roundup — your no-fuss guide to the tech stories that actually matter if you’re running a small business or just trying to keep your home setup safe and sorted. Grab a brew; here’s what happened this week.
OpenAI Says We’ve Hit the AGI Moment
In what is probably the biggest AI headline in years, OpenAI released a new flagship model this week and boldly declared it the beginning of the AGI era — artificial general intelligence, the long-held goal of building systems that can outperform humans across most meaningful, economically valuable tasks. The new model is rolling out now, and early reports suggest it represents a significant leap rather than a modest upgrade.
Whether you believe the “AGI” framing or find it a touch dramatic, the practical upshot is that AI tools are about to get noticeably more capable. If you’ve been using AI writing or productivity tools — Notion’s AI features and Grammarly are good everyday examples — expect the underlying smarts powering tools like these to improve considerably over the coming months.
What this means for you: AI assistants are becoming genuinely more powerful, so now’s a good time to explore how they could save you time at work — just keep a human eye on anything they produce.
Microsoft’s Monster Patch Drop
Microsoft pushed out its biggest-ever single batch of security fixes this week, plugging nearly 1,000 vulnerabilities across Windows and its wider software catalogue. The company says AI is helping it find bugs faster — which sounds reassuring, until you realise the sheer volume of patches is itself becoming a headache for IT teams and small business owners who have to actually test and apply them.
This isn’t a reason to panic, but it is a reason to act. Unpatched systems are one of the most common ways attackers get in, and with nearly a thousand holes now publicly known about, the window between “patch released” and “attackers exploiting it” is shrinking.
What this means for you: Go and check Windows Update on your machines today — seriously, don’t put it off. If you manage several PCs for a small business, consider whether a simple patch management routine is worth setting up.
Hackers Used USB Sticks to Backdoor Executives’ Laptops
This one reads like a spy thriller. A Chinese state-linked hacking group reportedly broke into hotel rooms at an industry conference this spring, waited until the executives were at dinner, and then booted their laptops from USB sticks to install backdoor software — all without needing a password or network access. The attack method exploited a well-known vulnerability that a firmware-level fix exists for, but which most organisations simply hadn’t applied.
The fix in question involves configuring machines to prevent booting from external devices unless authorised — something that’s often left switched off by default. It’s a stark reminder that physical security matters just as much as digital security, and that “we have a fix available” means nothing if it’s never deployed.
For anyone travelling with a work laptop — particularly to conferences or overseas trips — a VPN like NordVPN is a sensible layer of protection on unfamiliar networks, but physical access to your device is a whole separate risk that needs thinking about too.
What this means for you: If you travel with a laptop, talk to whoever manages it about disabling USB boot options, and never leave devices unattended in hotel rooms if you can help it.
AI Agents Linked to a Real-World Supply Chain Attack
Researchers this week published findings suggesting that a coordinated attack on RubyGems — a widely used package repository for software developers — was carried out by a swarm of AI agents rather than human hackers. The attack gained the ability to run malicious code on servers, raising serious questions about AI being weaponised for cyber attacks at scale and speed no human team could match.
This is still an emerging area, but it signals a shift: AI isn’t just a tool for defenders, it’s increasingly being used offensively too. For small businesses that rely on third-party software or plugins, supply chain attacks are a growing risk worth keeping an eye on.
What this means for you: Keep your software and plugins updated, stick to reputable sources, and consider whether your security tools are keeping pace — good endpoint protection is more important than ever.
That’s your week in IT. Between a landmark AI release, a near-thousand-strong patch drop, old-school USB spy tricks, and AI-powered attacks, it’s been a week that proves the threat landscape and the toolbox are both evolving fast. Stay patched, stay cautious, and we’ll see you next week.