This Week in IT: Key News

⚠️ Some links on this site are affiliate links. If you buy through them, we earn a small commission at no extra cost to you. This never influences our reviews.

Welcome back to the itpick weekly news roundup — your no-nonsense guide to what happened in tech this week and, more importantly, what it actually means for you and your business. It’s been a busy one.

OpenAI Says We’ve Reached AGI — Meet GPT-6 Astra

OpenAI made a pretty staggering announcement this week, releasing a new frontier model called GPT-6 Astra. The company is going as far as to say this marks the beginning of the AGI era — that’s artificial general intelligence, the long-held goal of building AI systems capable of outperforming humans at most economically meaningful tasks. Bold claim, to say the least.

For everyday users and small businesses, what this practically means is a significant leap in what AI assistants can do — from writing and analysis to coding and reasoning. OpenAI isn’t alone in pushing hard this week either: Microsoft released a new speech-recognition model called MAI-Transcribe-2 that it claims is faster, cheaper, and more accurate than rivals from Google and others. AI transcription tools are genuinely useful for small teams — think meeting notes, customer call summaries, or dictating documents without a PA.

If you’re already using AI writing tools like Grammarly or organising your work through Notion, it’s worth keeping an eye on how these newer models start feeding into the tools you use day-to-day. Things are moving fast.

What this means for you: AI is getting more capable and cheaper to access — now’s a good time to experiment with tools that could save your team real hours each week.

Microsoft Patches Nearly 1,000 Security Flaws in One Go

In what’s being described as the largest single patch release Microsoft has ever put out, the company this week pushed fixes for close to 974 security vulnerabilities across Windows and its wider software catalogue. Microsoft has credited AI with helping it find vulnerabilities faster — which sounds great, until you realise that security professionals are now warning that the sheer volume of patches is becoming a problem in itself. Many organisations simply can’t test and deploy fixes quickly enough.

For home users and small business owners, the message is simple: make sure Windows Update is turned on and set to install updates automatically. If you’re managing a handful of machines for a small team, don’t let those update prompts pile up. Some of those 974 flaws will be serious enough to be actively exploited before patches are applied.

What this means for you: Enable automatic updates on all your Windows devices now — the longer you wait, the bigger the window for attackers.

Hackers Broke Into Hotel Rooms to Backdoor Executive Laptops

This one reads like something out of a spy thriller, but it’s entirely real. A China-linked hacking group physically broke into hotel rooms during a business conference on Hainan Island this spring. While executives were out at dinner, attackers booted their laptops from USB sticks and installed backdoors — no phishing, no dodgy emails, just old-fashioned physical access. CrowdStrike, which tracked the campaign, noted that the attack exploited a configuration that many companies had a fix for but hadn’t actually applied.

Now, most people reading this aren’t attending high-stakes industry conferences in China — but the lesson here travels. Physical access to your devices is a major risk that often gets ignored. If you travel for work, consider a VPN like NordVPN to secure your connection on hotel Wi-Fi, use full-disk encryption, and set a BIOS password to prevent anyone from booting your laptop from an external device. A password manager like NordPass also means your credentials aren’t stored in a browser that someone could easily access on a compromised machine.

What this means for you: Physical device security matters — especially when travelling. Lock it down before you leave.

AI Was Used to Chain Flaws and Hijack OpenAI Staff Accounts

Rounding out a week heavy on AI and security crossover, researchers at a firm called Hacktron used Anthropic’s Claude Opus 5 to help chain together two separate software vulnerabilities and ultimately take over the accounts of several OpenAI employees, reaching an internal code repository in the process. This was legitimate security research, not a malicious attack — but it’s a striking demonstration of how AI can accelerate the discovery and exploitation of weaknesses.

For more on how Claude compares to other AI assistants, see our guide: Claude

What this means for you: AI isn’t just a productivity tool — it’s also becoming a weapon in the security researcher’s (and attacker’s) toolkit. Strong, unique passwords and multi-factor authentication are more important than ever.


That’s your week in IT. Between a landmark AI launch, a record-breaking patch drop, spy-movie-style laptop hacking, and AI-assisted account takeovers, it’s fair to say the pace isn’t slowing down. Stay patched, stay alert, and we’ll see you next week.


Further Reading

AI tools cybersecurity Windows updates OpenAI hacking