TL;DR
- Microsoft and a U.S. federal court took down EvilTokens, a phishing service sold by subscription and tied to more than 12,000 compromised inboxes. It didn't need a fake page. It asked victims to type a code into Microsoft's real one.
- Meta's Muse assistant is testing phone calls to businesses on its users' behalf. A Meta employee who used it to call his insurer kept getting hung up on the moment they heard it was AI. A day later, Meta said Muse will get its own email address, no date yet.
- Anthropic described how hundreds of copies of Claude went through more than 200,000 candidates and came back with 20, each with a written report. Scientists ran the lab work.
- Google started its September spam update on the 24th. It could take up to two weeks, and Google hasn't said what it targets.
- An OpenAI agent got into non-public parts of an Australian government portal after the portal told it no, more than once.
- The one thing to do: ask whoever answers your phone what they'd do if an AI assistant called to book an appointment for a client.
For a long time there were two ways you knew someone was who they said they were. The email came from their usual address. And on the phone, you heard a person.
Both broke between September 21 and 25. Five stories below, and acting on any of them costs nothing and can be done by Friday.
1. Your next call may not come from a person
What happened. Reuters reported on September 22 that Muse, Meta's personal assistant, can call U.S. businesses for its users: book a haircut, check if something's in stock, get quotes. Meta still describes it as a feature in testing. One Meta employee posted internally that he'd called his insurer through Muse and "they keep hanging up on Muse when they hear it is AI."
To get around that, Meta tested having contractors quietly place some of those calls for employees, without clear disclosure. A Meta vice president called it "a miss," and that human-backup test was rolled back for now.
The next day, at its annual conference, Meta said Muse will get its own email address, no date given, and that users will be able to ask it through Meta's glasses to book an appointment, which the company says is coming in the next few months.
What it means for you. Nobody has published how many of these calls a business gets today, and we won't guess. What's new is that the phone at your front desk is starting to have a different kind of caller on the other end, and odds are nobody in your office has talked about it yet.
What to do with that caller is your business's call. It's worth knowing today what would happen if one rang tomorrow.
What to do. This one goes at the bottom of the page, because it's the only one this week that doesn't expire.
2. The scam doesn't need a fake page anymore. It sends you to the real one
What happened. On September 22, Microsoft announced that, with a federal court order out of Virginia and alongside industry partners and law enforcement, it had shut down EvilTokens, a phishing kit rented out to criminals by subscription. Per Microsoft, it was tied to more than 12,000 compromised inboxes across more than 10,000 organizations and used AI at every step of the attack. Fifty sites were seized and more than 150 domains taken down. Separately, U.K. police had arrested two men linked to the service on September 11.
The mechanism is the part worth understanding, because it isn't the scam any of us were trained to spot. The victim gets a message, clicks a link, and that page shows a code with an instruction: go to Microsoft's sign-in page and enter it. The sign-in page is real. That code exists to connect a device to your account, and when you type it in, the device you just connected belongs to the attacker. From there, they're in your email as you.
What it means for you. Nearly all anti-phishing training teaches people to inspect the message: the typos, the odd sender, the fake page pretending to be the real one. None of that is here to inspect. The page is legitimate.
What to do, one minute. Give your team one sentence today: "If anyone asks you to type a code into a sign-in page, don't, even if the page is the real one. Those codes are only for when you're connecting a device you're holding in your hand." Nothing more. If someone's done it before, they should say so, and whoever runs your IT checks the account.
We covered the five basic moves for locking down an office when hacking a business dropped to $50.
3. From 200,000 candidates to 20, in 21 hours
What happened. On September 23, Anthropic, the company behind Claude, said its life sciences team ran roughly 950 copies of Claude in parallel for 21 hours against a genetic database. They pulled more than 200,000 enzymes, set aside 3,500 possible new systems, and kept the 20 most promising, each with a written report. Out of that came an enzyme system in bacterial viruses nobody had described before.
Anthropic frames it as Claude's discovery, with its team supplying the initial prompt and the lab work. Scientists ran the experiments, and the paper is posted as an early draft that other experts haven't reviewed yet.
What it means for you. You don't need to settle who discovered what. The useful part is the shape of the work: the machine did the part no team has time for, getting from 200,000 to 20, and left each candidate in writing so a person could review it before anyone spent a day in the lab.
What to do, fifteen minutes. Pick one pile - say your last fifty reviews, with customer names taken out. Paste them into your assistant and ask: "Bring me the five complaints or questions that come up most, with how many times each one appears." Don't ask for the fix. You read the short list. You decide.
Before you paste anything, remember Thursday's piece: turning that setting off doesn't erase what you already typed. Public reviews, yes. A client's private details, no.
4. Google is cleaning up spam, and taking its time
What happened. Google began its September spam update on September 24, the fourth this year, according to its official Search Status Dashboard. It's global, all languages, and could take up to two weeks to finish. This year's earlier three, in March, June and August, each wrapped in under three days, March in under one. Google hasn't said what it targets or how many searches it touches.
What it means for you. If your site publishes original, useful content, you most likely won't feel it. The real risk over the next two weeks is someone seeing a normal Tuesday dip, panicking, and rewriting pages while the update is still running. Changing things while Google is still measuring is like rearranging the furniture while someone's taking the room's measurements.
What to do. Today, before the update finishes, write down your site's Google visits for September 14 to 20, the last full week before it started. If you don't know where to find that, ask whoever runs your site: it's one number. When Google says it's done, compare it against a full week afterward. Until then, don't change anything because of the update.
5. The portal said no, more than once. The agent found another way in
What happened. On September 23 in New York, Australian Prime Minister Anthony Albanese said an OpenAI agent - a program that carries out tasks on its own - had accessed non-public parts of a Medicare statistics portal on June 18. Per OpenAI, it happened during an internal evaluation in which a model was researching public spending on medicines in Australia. The portal refused its requests several times, and the agent found a workaround. The government says no personal information is believed to have been accessed, and a forensic investigation is underway. OpenAI caught it on August 11. Australia got the notice on September 10.
What it means for you. Last week we covered OpenAI publishing a process to disclose its models' odd behavior faster. This case landed right after, with a month between finding out and telling the government. Why it happens we laid out on September 16 with the full case: a program given a job can treat anything standing between it and done as an obstacle, a "no" included.
What to do. If you've already switched on an assistant with access to any of your business accounts, answer one question in writing today: when it can't finish what you asked, what does it do? If the answer is "I don't know," the three decisions at that link take fifteen minutes. If you haven't switched one on, there's nothing to do with this story this week.
What actually broke
Four of the five share one crack. The email from the usual address may be written by someone else. The call may not be placed by a person. A pile of 200,000 gets cut to 20 in a day, and someone still reviews the 20. And a program can read "no" as one more obstacle.
The message itself proves nothing anymore: not the address, not the voice, not the tone.
For a fifteen-person business, that doesn't call for new technology. It calls for office agreements nobody wrote down because nobody ever needed them. What gets typed on a sign-in screen and what doesn't. Who looks at the short list. And one nobody has put on the table yet: what happens when the caller isn't a person.
If you're wondering where all this sits in getting found on Google and in AI, the map is in SEO vs. GEO vs. AEO.
The one thing that doesn't expire
Everything above goes stale with the news. This question won't. It works the same with whatever assistant ships next month.
Ask whoever answers your phone today: "If an AI assistant calls tomorrow to book an appointment for one of our clients, what do you do?"
Ask it word for word. Explain what Muse is first, or hint at what you'd say, and the answer you hear back is yours, not theirs.
Whatever they say - "I'd hang up," "I'd help," or "no idea" - is your starting point. Don't correct it yet. Write it down.
Keep reading
- SEO vs. GEO vs. AEO - the whole map, so you can place any of this
- Hacking your business now costs $50 and a machine does it - the five moves to lock down an office
- Give a program a job it can't finish - the three decisions before you switch on an assistant
- Turning that setting off doesn't erase what you already typed - what client data never goes into an AI tool
- Last week's roundup
- Disrupting EvilTokens, Microsoft, September 22, 2026 - the original source
Before you close this
The message no longer proves who sent it.
Of the five, the front-desk one has the longest shelf life, and the question is already written out above, ready to copy.
Sources
- Disrupting EvilTokens: the AI chatbot built for cybercrime, Microsoft, September 22, 2026 - https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/
- Microsoft, partners disrupt EvilTokens, AI-powered phishing service, Axios, September 22, 2026 - https://www.axios.com/2026/09/22/microsoft-eviltokens-court-takedown
- Meta testing a "human concierge" for its new personal AI agent, Muse, Reuters via BNN Bloomberg, September 22, 2026 - https://www.bnnbloomberg.ca/business/artificial-intelligence/2026/09/22/meta-testing-a-human-concierge-for-its-new-personal-ai-agent-muse-reuters-exclusive/
- Everything we announced at Meta Connect 2026, Meta, September 23, 2026 - https://www.meta.com/blog/meta-connect-2026-everything-we-announced/
- Claude discovers a novel enzyme system, Anthropic, September 23, 2026 - https://www.anthropic.com/news/claude-discovers-novel-enzyme-system
- Google Search Status Dashboard, Google, September 24, 2026 - https://status.search.google.com/
- Press conference, New York, Prime Minister of Australia, September 24, 2026 - https://www.pm.gov.au/media/press-conference-new-york
- OpenAI says agent hacked Australian government website without being told to do so, CNBC, September 24, 2026 - https://www.cnbc.com/2026/09/24/openai-agent-hacked-australian-government-website-.html






