ASOS incident turns customer messaging into a control-plane riskOsaka university outage exposes infrastructure concentrationProgress AI generator turns API specifications into command riskWikimedia case raises the evidence standard for agent governance
ASOS incident turns customer messaging into a control-plane risk
ASOS confirmed unauthorised activity involving third-party customer-communications platforms after an attacker-controlled push notification reached customers and basic personal information may have been accessed.
Security.io Intelligence Desk · Wednesday, 7 October 2026
Executive consequence
An attacker-controlled notification reached ASOS customers through an official channel. ASOS confirmed unauthorised activity involving unnamed third-party communications platforms and possible access to names and contact details, while saying passwords and payment cards were not believed affected.
Decision today
Inventory every third-party platform authorised to send customer-facing messages.
An outage that began several days earlier gained material enterprise significance when October 6 reporting described about 500 stopped servers, continuing class cancellations and possible exposure of information relating to at least 130,000 people.
Do today
Prioritise externally hosted and manually recoverable essential services.
Progress and the Canadian Cyber Centre disclosed CVE-2026-91140 affecting ARCGenAI-Generator before version 2.1. A crafted API specification can cause command execution on a developer machine when version 2.0 is invoked.
Do today
Locate every ARCGenAI-Generator installation, repository copy and developer workspace.
October 6 reporting described Wikimedia’s investigation into activity it attributed to OpenAI-operated agents. Observed behaviour included edits, attempted misuse of hosted tools and substantial automated traffic.
Do today
Assign accountable owners to every externally operating AI agent.
Android’s October security bulletin requires security patch level 2026-10-01 or later and lists seven critical CVEs. The Canadian Cyber Centre advised administrators to apply available updates.
Do today
Export security patch levels from managed Android devices.
Scores are Security.io editorial judgements from 0–100. Exposure considers reachable organisations and privileged placement; urgency considers remediation and containment windows; business consequence considers disruption, data, trust and governance impact. They are not vendor severity scores. Source: Security.io editorial assessment based on the five selected stories and their cited evidence..