By Ayu, Cybersecurity Operations, Jutsu

AI agents are not news anymore. They triage tickets, write code, browse the web, and run in half the tools your company pays for. What I keep noticing is how little has changed about the way they get access. This week gave a pretty clear picture of what that looks like in practice.
Wikimedia and the OpenAI agents
Wikimedia says it found edits to its wikis, some failed attempts to exploit a public note-taking tool it hosts called Etherpad, and a lot of unusual traffic, all suspected to come from agents operated by OpenAI. It started looking after earlier reports from Hugging Face and DseWiki, where the agents reportedly used a wiki forum as an unofficial bulletin board to talk to each other and chained online services together to reach the internet and cover their tracks. I have not seen OpenAI’s side yet, so this is reported, not proven. But the part that matters is that the people who noticed were the ones whose infrastructure got used, not the ones running the agents.
Apple tightens Full Disk Access
Apple announced it is tightening macOS Full Disk Access because of the risks AI agents create. That permission exposes files, mail, messages and browsing history, and an agent that gets it can read all of it.
Google pauses open source bug bounties
Google paused bug bounty rewards for its open source projects on October 1 after a surge of automated submissions, most of which it says were not valid. It did not say AI produced them, so I will not either.
OX Security and 15,465 MCP servers
OX Security looked at 15,465 public MCP servers and found no real review process in the marketplaces, with security treated as a recommendation instead of a policy. That is vendor research, so take it with that in mind, but it lines up with how most of these ecosystems grow.
Denmark and the national population register
Denmark said attackers got names, addresses and ID numbers for about 8.8 million people from its national population register. They used a private company’s legitimate lookup right and ran huge numbers of automated queries to find valid ID numbers. No exploit needed, the access was already there.
The FBI, Accenture, and a missed patch
The FBI removed an Accenture contractor after a ShinyHunters breach exposed personal details of bureau employees, saying the contractor failed to apply a patch that had been issued. Reuters reportedly identified the platform as Oracle PeopleSoft. A missed patch and a third party, which is about as old as security stories get.
Why access keeps outrunning oversight
Agents, a lookup right, a contractor. Every one of these had legitimate access that nobody was really watching. In compliance, the questions behind almost every control are the same: who can touch what, who approved it, and what evidence shows someone is checking. Agents did not create those questions, they just make the answers matter more, because they act faster than a person can review and chain steps nobody planned.
If you run agents near real systems, the boring work is the work. Give them permissions on purpose, log what they do, and name a person who is accountable for the result.
Ayu works in Cybersecurity Operations and Compliance at Jutsu, where the team is building AgentSOC, an AI-powered Security Operations Center. If your SOC team is drowning in alerts, you know where to find us.