· artificial intelligence · 4 min read

AI and cloud briefing: a mystery AI model that beat GPT-5.6 turns out to be Chinese, Cl0p ransomware hits Shell and Philips, and Microsoft patches a Defender zero-day

An anonymous AI model that quietly outperformed GPT-5.6 on coding tests has been unmasked as a Z.AI release. The Cl0p ransomware group has now named over 40 victims, including Shell and Philips, in a campaign against PTC software. And Microsoft's August patches fix 421 flaws, including one already under attack.

An anonymous AI model that quietly outperformed GPT-5.6 on coding tests has been unmasked as a Z.AI release. The Cl0p ransomware group has now named over 40 victims, including Shell and Philips, in a campaign against PTC software. And Microsoft's August patches fix 421 flaws, including one already under attack.

Here is our latest round-up of what’s changing in AI and cloud for UK businesses, with links to the original sources so you can read further.

Lead story: a mystery AI model that beat GPT-5.6 turns out to be Chinese

On 20 August, an AI model with no company name attached appeared on the OpenRouter platform under the label “stealth/ox-alpha”. Independent testers ran it against real coding tasks and found it beat OpenAI’s GPT-5.6 and matched or beat several other leading models, sparking days of guessing about who had built it. Technical fingerprinting pointed strongly to Chinese AI lab Zhipu, and on 26 August the mystery ended: Z.AI (Zhipu’s commercial arm) released the model openly as GLM-5.3-Flash under a free MIT licence, meaning any business can download and run it themselves. Full detail is available from Pandaily.

An anonymous AI model called Ox Alpha beat GPT-5.6 on coding tests before being revealed as Z.AI's open-weight GLM-5.3-Flash

Why this matters: this is now a repeating pattern. Chinese labs are releasing genuinely competitive AI models under open licences, often for free, which lowers the cost of running capable AI for any business willing to host it themselves rather than pay for access through a big-name provider. It’s worth watching this space if your AI costs are climbing.

Cybersecurity: Cl0p ransomware group names over 40 victims including Shell and Philips

The Cl0p ransomware group has listed more than 40 organisations on its leak site, all breached through a critical flaw in PTC’s Windchill and FlexPLM software, tools used to manage product design and manufacturing data. Confirmed victims include Shell, Philips, Fiserv, Zebra Technologies and Largan Precision. The flaw, tracked as CVE-2026-12569, allows an attacker to run their own code on an exposed server without needing a password, and evidence shows Cl0p was quietly exploiting it as an unpatched “zero-day” for weeks before PTC issued a fix. Full detail is available from SecurityWeek.

The Cl0p ransomware group has named Shell, Philips and over 40 other organisations as victims of a campaign exploiting a flaw in PTC Windchill software

Why this matters: this is the same group behind several large-scale breaches in recent years, and the pattern is consistent, find one flaw in software used by many large companies, then hit them all at once before most can patch. If your business uses any product lifecycle or engineering software, check with your vendor now on patch status rather than waiting for an incident.

Patch management: Microsoft fixes 421 flaws, one already being exploited

Microsoft’s August Patch Tuesday release addressed 421 separate security flaws across its products, one of the largest single updates of the year. Among them is a high-severity vulnerability in Microsoft Defender, dubbed “ShieldBreak” and tracked as CVE-2026-69414, which lets an attacker who already has limited access to a machine escalate their privileges to take fuller control. Microsoft has confirmed this flaw is already being exploited in the wild. Full detail is available from SecurityWeek.

Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including a Defender privilege-escalation flaw already being exploited

Why this matters: a flaw in Defender itself, the tool meant to protect a machine, is a useful reminder that security software is not immune to vulnerabilities. If your IT team or provider hasn’t applied August’s updates yet, this is one to prioritise rather than leave until the next routine maintenance window.

The takeaway

Today’s stories point to two trends worth tracking: capable AI is becoming cheaper and easier to access outside the usual big-name providers, and attackers continue to move fast on newly disclosed software flaws, often faster than the affected companies can patch. We can help you assess whether open-weight AI models are a fit for your business, check your exposure to the PTC Windchill flaw if you run product lifecycle software, and confirm your systems are current on August’s security updates. Get in touch.


AI Agent based research and content, AI can do mistake, please help us to improve.

Back to Blog