Australia weighs AI copyright changes as AI giants push for greater access to training data

Posted in Commentary with tags , on October 6, 2026 by itnerd

Australia is weighing new rules governing AI as executives from Anthropic and OpenAI appeared before a parliamentary inquiry Tuesday to address AI safety, cybersecurity incident reporting, model training and the country’s existing laws, according to ABC News.

Both Anthropic and OpenAI said they would support laws requiring AI companies to report breaches carried out by their agents. OpenAI Chief Strategy Officer Jason Kwon said a legal framework could establish a standard for when incidents must be disclosed rather than leaving those decisions solely to AI companies. Anthropic’s Australian policy chief David Masters similarly said the company would be open to mandatory disclosure requirements.

The hearing also examined how Australia’s existing copyright laws apply to AI training. Anthropic told lawmakers that requiring licenses for every piece of online content used to train models would be technically unworkable, while Australian media and creative-industry representatives opposed proposals that could allow AI companies to use material unless rights holders specifically opt out.

OpenAI acknowledged at Tuesday’s hearing that its internal escalation and notification process should have been better. The parliamentary inquiry is holding hearings through October 9 and is expected to issue its final report by November 30.

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Australia’s AI hearing links security and copyright through one accountability problem. Creators and affected organizations are being asked to absorb the cost of AI companies operating at scale.

“A proposed opt-out copyright model would make rights holders police whether their work enters model training. With incident reporting left to company discretion, affected organizations can wait while a provider decides whether an agent’s unauthorized access deserves disclosure.

“OpenAI’s agent accessed Australia’s Medicare statistics reporting service, and the company took three months to notify the government. OpenAI Chief Strategy Officer Jason Kwon said the company should have handled the response better, while both OpenAI and Anthropic backed mandatory disclosure laws. Mandatory reporting works when the clock starts at the first unauthorized tool call. In my work with agentic systems, authorization is the control point. The provider can investigate whether data was copied while the regulator already knows an incident occurred.

“Copyright needs the same discipline. Anthropic says licensing every piece of online content would be technically unworkable, while the Australian Broadcasting Corporation’s Kate Gilchrist told the inquiry an opt-out model puts the burden on rights holders. The answer to a licensing problem cannot be asking writers, publishers, musicians, and developers to patrol the internet for every training use.

“Australia should require the companies controlling the training pipeline and agent runtime to carry the cost of consent, evidence preservation, and disclosure.”

ㅤ

Ryan McCurdy, VP of Marketing, Liquibase:

“As AI agents start taking actions across more systems, incident reporting is going to depend on having a clear record of what they actually did.

“Knowing an agent accessed a system isn’t enough. You need to know what it changed, what policies it passed, what authorized the action, and what actually happened as a result. That evidence needs to be created as the agent works. If something goes wrong, you shouldn’t have to piece together the agent’s actions after the fact.

“The more authority we give AI to act on its own, the more important that trail becomes.”

Australia has the right idea here. And knowing them, they are also willing to apply strict enforcement as well. The question is if OpenAI and Anthropic will listen and take the right action so as to not fall victim to this law.

OpenAI “Rogue” Agents Discovered on Wikimedia Platforms

Posted in Commentary with tags on October 6, 2026 by itnerd

The Wikimedia Foundation said they have discovered “rogue” OpenAI agents on Wikimedia platforms. The unauthorized bot activities included edits to wikis, some unsuccessful attempts to exploit a public note-taking tool they host, and heavy traffic.

More info here: https://wikimediafoundation.org/news/2026/10/05/openai-rogue-agent-activities-found-on-wikimedia-projects/

Ensar Seker, CISO at SOCRadar, provided the following comments:

“Wikimedia reports that the Etherpad exploitation attempts were unsuccessful and that it found no evidence of compromised systems or data. That distinction matters. Even so, the incident exposes a serious control problem: agents attributed to OpenAI were able to interact with third-party infrastructure beyond their intended boundaries, attempt to repurpose public services as proxies, and generate traffic at a scale that imposed costs on an outside organization.

We should be careful with the word ‘rogue,’ because it can make this sound like science fiction. The practical security issue is excessive autonomy combined with inadequate containment. An AI agent should be treated like any other potentially untrusted workload: give it a unique identity, minimum permissions, tightly restricted network access, approved tools and destinations, strict rate and spending limits, complete audit logs, and an automatic way to terminate abnormal behavior.

The organization operating an agent remains responsible for its actions. When an agent reaches beyond its authorized environment, affected parties need prompt notification and usable technical indicators. Open platforms such as Wikimedia should not be expected to absorb the security and infrastructure costs of someone else’s experimentation. Agent developers must design for containment before deployment, rather than relying on third parties to detect and clean up the consequences.”

This is yet another example of OpenAI agents going rogue. Which is horrifically bad. That needs to change ASAP because this way too often.

FusionAuth Establishes UK Team as European Demand for Data Sovereignty Drives 72% Regional Growth

Posted in Commentary with tags on October 6, 2026 by itnerd

FusionAuth today announced accelerated momentum across Europe, powered by rising enterprise demand for data sovereignty, tenant isolation, and infrastructure control.

In its fiscal first quarter ended July 31, 2026, FusionAuth grew new-business annual recurring revenue (ARR) by 48% year-over-year and increased new customer acquisitions by 40%. Regional European ARR grew 72%% over the past two years—contributing over 30% of Company ARR -—all before FusionAuth had a dedicated team in the region. In response to that growth, FusionAuth has established its first European sales presence, based in the United Kingdom.

European focus on digital sovereignty continues to intensify, with EU initiatives placing greater emphasis on cloud sovereignty, interoperability, portability, and control over data infrastructure. According to Gartner, European sovereign-cloud IaaS spending is forecast to rise 83% in 2026. FusionAuth’s 2026 State of AI and Identity Report also found that 85% of technology leaders have faced customer, partner, and supplier demands to demonstrate tenant isolation as an enterprise buying criterion.

This need for control is especially important in consumer-facing sectors, where a brand’s relationship with its customers, and the identity and data behind it, is too valuable to hand to a shared platform. That momentum is clear across FusionAuth’s fastest-growing verticals, anchored by European market leaders:

  • Media & Telecom: ARR grew 70% in the last year and over 90% across two years, led by media intelligence provider UNICEPTA and a major European news publisher.
  • Energy & Utilities: Customer count surged 120% in the last year, driving two-year ARR growth over 90%, including German smart-home energy pioneer tado° and mobility platform MKB Brandstof.
  • Retail & Consumer Goods: ARR increased 65% over two years on larger enterprise deployments, including French supermarket leader Grand Frais and premium skincare brand Elemis.

That same emphasis on owning the customer relationship applies directly to professional sports, where multiple premier football clubs and governing bodies rely on FusionAuth to secure and unify fan identity. On October 7-8, FusionAuth is co-sponsoring The Fan Identity Forum at Leaders Week London–gathering over 3,000 senior sports decision-makers at Stamford Bridge. Partnering with sports digital product specialist  Stadion, FusionAuth will address the impact of AI and the strategic necessity to identify and own the fan relationship across ticketing, merchandising, streaming, and matchday experiences.

CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure

Posted in Commentary with tags on October 6, 2026 by itnerd

SOCRadar’s Threat Research Unit (STRU) has today published a new piece of research on CyberXero, a Russian-speaking Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer running on its own infrastructure. 

The operation runs two pipelines at once: a global, automated campaign against WordPress and e-commerce platforms, and a curated, manual campaign against Ukrainian energy and critical infrastructure. More than 628,000 Ukrainian individuals have confirmed data in the actor’s possession, including residents of Kharkiv, a city on an active war front.

Significantly, the entire operation surfaced from a single configuration error.

For the complete technical analysis, here is the full PDF report: https://socradar.io/resources/report/cyberxero-threat-research-report/

The blog covering the key points is accessible here: https://socradar.io/blog/cyberxero-ai-iab-ukraine-critical-infrastructure/

FBI removes Accenture contractor after an unpatched third-party PeopleSoft platform exposed employees’ counterintelligence roles and medical records

Posted in Commentary with tags on October 6, 2026 by itnerd

The FBI removed an Accenture contractor on Monday after a data breach exposed sensitive personal details of thousands of bureau employees, Reuters reported. FBI cyber chief Brett Leatherman said the incident “occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform.”

More info here: FBI removes Accenture contractor after ShinyHunters data breach

Jason Brown, Director of Customer Advisory, Counter Fraud Lead, iCOUNTER

“The FBI breach came through a PeopleSoft HR platform that a third party managed. According to the FBI, a contractor failed to apply a patch that Oracle and Google flagged as critical back in June. ShinyHunters claims it got in through that flaw in September. Third-party risk lives in that gap. Organizations hand third parties some of their most sensitive systems and then have very little insight into whether those systems are patched, monitored or exposed. In this case, Reuters reports the result was counterintelligence role descriptions, home addresses of human intelligence operatives, and medical and psychiatric records for bureau employees. Every contract for a managed platform should spell out how quickly critical patches have to be applied, require the third party to prove it was done, and give the customer the right to check. Security teams also need to stop treating third-party managed systems as someone else’s problem. Keep an inventory of every platform a third party runs on your behalf, know what data sits in it, and watch for warning signs, like that platform showing up in exploit activity or criminal forums. Groups like ShinyHunters look for exactly this kind of weak link, because one unpatched platform at a contractor can expose an entire workforce. Intelligence on which of your third parties are being actively targeted gives you a chance to act before the data is gone. Outsourcing the platform leaves the accountability with you. When it’s your employees’ data, the breach is yours.”

ShinyHunters is busy for sure. Thus proving that this wasn’t going to stop them. Thus if I were you, I would harden things up so that ShinyHunters don’t get in at all.

UPDATE; More commentary has come in.

Justin Beals, CEO & Founder, Strike Graph

“The FBI deserves credit for saying plainly what happened. A contractor failed to apply a patch that was explicitly issued to secure the platform, and the bureau named that as the cause and removed the contractor. Most organizations would bury that finding. The harder truth is that the FBI’s workforce data was only as secure as the patch cadence of a team it didn’t directly manage.

Federal contracting keeps running into this gap. Agencies and primes collect attestations that controls are in place, but an attestation only tells you what a vendor intended to do. It doesn’t tell you whether the patch went in after Google warned that ShinyHunters was going after vulnerable PeopleSoft instances. A DHS prime contractor I work with put it to me directly when we were talking about his obligations as an affirming official: ‘I don’t think a security questionnaire is going to cut it.’ He’s right. A questionnaire is self-attested and unverifiable, and he’s signing for every subcontractor below him.

Expect this to show up in enforcement. DOJ recovered $52 million under its Civil Cyber-Fraud Initiative in FY2025, and those cases turn on the gap between what a contractor said about its controls and what was actually running. Removing the contractor was the right call, but it happened after the damage was done. The agencies and primes that avoid the next headline will be the ones requiring continuous evidence from their suppliers, including time-to-patch on critical systems, rather than a form that gets filed once and never revisited.”

Joe Brinkley, Director of Offensive Security Research & Community, Cobalt

“Outsourcing the management of a platform doesn’t outsource the risk that comes with it. Attackers understand this well, which is why groups like ShinyHunters focus on widely deployed enterprise applications where responsibility for patching sits somewhere between the customer and the service provider. When ownership is split, critical updates tend to fall into the gap, and that gap is where real-world exploitation happens. The approach also scales well for attackers: once they have a working method against one platform, they can sweep the internet for every instance that’s lagging behind, regardless of who manages it. Organizations need to treat third-party-managed systems as part of their own attack surface. That means setting clear contractual ownership of remediation timelines and independently validating that patches were actually applied, because a status report is not evidence that the exposure is gone. The organizations that hold up best test their trusted relationships the same way an attacker would, rather than assuming someone else has it covered.”

Wise Becomes First App to Offer Both eSIM and QR Payments Across Five Continents

Posted in Commentary with tags on October 6, 2026 by itnerd

Ahead of the peak year-end travel season, Wise has launched a direct fix for “arrival anxiety” – the universal moment of panic of landing in an unfamiliar country without mobile data or the local way to pay. By combining customisable eSIM data plans with an unmatched cross-border QR code scanner that works across five continents, Wise becomes the first to combine the two in one app.

A new Wise-commissioned YouGov survey of more than 14,000 travellers across eleven countries, found that 62% of adults who have travelled internationally in the last year rely on hotel or accommodation Wi-Fi to stay connected abroad. Once outside their hotel, travellers resort to comical behaviours to stay connected:

  • 24% of travellers have bought something at a café they did not want, purely to get free Wi-Fi.
  • 15% have stood outside a museum or tourist attraction to use their free Wi-fi instead of going inside.
  • 7% have asked a total stranger to share their phone’s personal hotspot.

Cash management was the most common payment problem reported abroad (43%). Of those who experienced challenges almost 40% of travellers said they missed out on local experiences like street food markets. Wise is solving both these pain points: the eSIM keeps people connected, while the extensive QR code payments network helps travellers pay like a local.

Waste-free, Build-Your-Own eSIM plans

The Wise eSIM introduces a highly flexible model to a telco market historically defined by rigid, pre-packaged expensive roaming plans. Alongside standard regional plans in more than 150 destinations, Wise is among the first in the world to launch customisable data plans to customers in the UK, EEA, US, Canada, Brazil, Singapore, Malaysia, Australia and New Zealand, giving travellers the power to design the type of coverage:

  • One-time eSIM installation: Customers only need to download the eSIM to their device once rather than for each individual trip.
  • Custom Controls: Travellers can buy the data directly from the Wise app, set the exact data allowance and the exact number of days they need, mapped perfectly to their itinerary.
  • Data Estimation Guidelines: Intuitive, in-app guidelines to help customers avoid over or under-buying data before they depart.
  • Unused Data Plan Refund: Wise will refund travellers for any unused data plans they purchase but do not use. Handy for those times when travel plans change.
  • Instant Activation: The data will only be used when the eSIM is connected to the supported network at the destination.

One app for the world’s QR codes

While cards work at hotels or airport duty-free shops, daily life down on the street moves to its own rhythm. Many countries around the world run completely on individual domestic QR codes. Because these systems were built for locals, foreign travellers have historically been locked out – forced to either track down physical cash at ATMs or sign up for a messy folder of single-use local e-wallets. Wise has broken down this barrier by becoming the first to bring together QR codes from five continents into one app.

  • Pay like a local from Singapore to Budapest to Rio de Janeiro: Wise’s direct connections with local payment schemes such as PayNow (Singapore), QR Ph (Philippines), DuitNow (Malaysia), Pix (Brazil), PromptPay (Thailand), Swiss QR-bill (Switzerland) and Qvik (Hungary) means that for the first time, all of these local payment schemes are now available in one place – through the Wise app.
  • Unlocking cashless payment in the Chinese mainland and beyond: Through a strategic partnership with the Alipay+, Ant International’s unified wallet gateway, Wise has simplified payments for travellers visiting Asia. In the Chinese mainland, where cash and foreign card payments are not commonly accepted, eligible Wise travellers can scan the QR and pay at millions of local Alipay+ enabled merchants directly through the Wise app without needing a Chinese bank card, local mobile number, or separate app setup required. The partnership enables Wise users to make cross-border QR payments in 50+ destinations globally including Hong Kong, Nepal, Korea, Sri Lanka and Cambodia.

Smart travelling with the Wise account

Beyond eSIM and QR codes, the Wise Account has also added pay as you go airport lounge passes, country guides with destination tips, as well as features like multi-currency bill split and group spending to make managing navigating new countries and managing money with friends and family a breeze.

Wise eSIM plans and QR payments are available in the Wise Account from today.

ASOS Attack: Cyber Extortion Is Becoming a Public Pressure Campaign

Posted in Commentary with tags on October 6, 2026 by itnerd

For those not in the know. ASOS is a company that makes high performance cycling clothing. The pro team EF Education use their gear. And I own a number of their items myself. And they have been pwned. But it’s different There has been a major shift in cyber extortion because of this attack: Attackers are bypassing private negotiations and going directly to customers, using trusted channels to create immediate public and market pressure.

More details here: ASOS app users receive notifications from hackers in apparent breach

Gina Cardelli, Director, Product Management at Fortra, shares what this attack means for organizations:

“The ASOS incident is still developing, but what is fact is that the attackers have demonstrated access to a trusted ASOS communication channel by sending a push notification directly to customers. If the Snowflake claim is legitimate, the potential impact could be significant. The standard dataset could apply like names, email address, billing/shipping addresses, but with the age of AI, retailers are also increasingly centralizing their customers behavioral, transactional, and demographic information to build better customer profiles. These profiles can provide attackers with material needed for highly convincing phishing, social engineering, account takeover, etc. 

This attack also reflects a shift in extortion tactics, to tell ASOS’s customers about the breach before the company does. The attackers bypassed the normal private negotiation between victim and attacker and brought customers, media, and investors to the table to watch. ASOS stocks dropped 13% after the push notification hit their customer base. Even if the attacker doesn’t have the data, they were able to create market pressure on ASOS with a single push notification. 

What I would watch for over the next 24 – 48 hours:

  1. A Formal statement from ASOS to confirm what has been compromised and the depth and breadth of the compromise
  2. A response from Snowflake, to understand if its isolated to the tenant or a Snowflake platform vulnerability 
  3. The attackers publishing sample records”

While there are a lot of hacks out there, given that this is a cycling clothing manufacturer, I will be watching this with interest in order to see what happens next.

UPDATE: Borja Rodriguez, Head of Threat Intelligence, Outpost24 has this to say:

“We found logins for 118 ASOS work email accounts in places where stolen passwords are shared online. For 22 of them, the password was recently stolen by malware, including staff sign-in and VPN logins. Exposure is not proof of involvement, but leaked logins like these are exactly what attackers look for.”

Q3 2026 Ransomware Roundup: Stats on attacks, ransoms, and active gangs

Posted in Commentary with tags on October 6, 2026 by itnerd

According to a new Comparitech study published today, Q3 2026 saw the highest quarterly figures to date with 2,627 ransomware attacks in total – an average of nearly 29 per day. This is a 29 percent increase on Q2 2026 which logged 2,030 attacks in total, and a 61 percent increase on the same period last year (Q3 2025). 

Additional key findings include:

  • Of 247 confirmed attacks:
    • 138 were on businesses
    • 53 were on government entities
    • 36 were on healthcare companies
    • 20 were on educational institutions
  • Of the 2,380 unconfirmed attacks*:
    • 2,096 were on businesses
    • 71 were on government entities
    • 152 were on healthcare companies
    • 55 were on educational institutions
  • Median ransom demand: $150,000 (average: $602,400)
  • The most prolific ransomware gangs were Qilin and The Gentlemen

For full details, the research can be read here: https://www.comparitech.com/news/ransomware-roundup-q3-2026-stats-on-attacks-ransoms-and-active-gangs/

Rebecca Moody, Head of Data Research at Comparitech, provided the following comment: 

“I’m often asked what I think lies ahead in the ransomware threat landscape, and it’s notoriously difficult to predict. Figures frequently fluctuate and a sector might see a bit of an increase one month, only to see a slight decrease the next month. However, Q3 2026 is different. We’re not seeing slight increases or decreases. We’re seeing significant increases across all key sectors.

Government agencies, healthcare providers, and the education sector all saw huge increases, as did the majority of business sectors. Seeing some of the most significant rises were tech companies (who often deal with multiple companies and are, therefore, a great central target for hackers), finance companies (who may also deal with a number of companies and/or store highly sensitive data), and utility companies (that form an integral part of our critical infrastructure). 

What’s also of note is hackers’ increasing attempts at triple extortion. They’re not only seeking to encrypt systems and steal data, but are also looking to target individuals/individual companies impacted in an attack. A prime example is The Gentlemen’s recent attack on MIP Holdings (a South African tech company). After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted. Over the last few weeks, however, The Gentlemen has started adding MIP’s clients to its data leak site in a bid to get a ransom out of them, too. A key reminder that paying a ransom is absolutely no guarantee that your stolen data will be deleted!”

Ahead of Samsung’s smart glasses launch, study reveals privacy risks across 7 rival brands 

Posted in Commentary with tags on October 6, 2026 by itnerd

With Samsung reportedly preparing to launch its first Android XR smart glasses in November, a new Cybernews analysis of 7 existing AI smart glasses brands reveals the privacy risks users may face as the technology becomes more widespread.

Researchers examined smart glasses from Meta, Rokid, RayNeo, INMO, Solos, Even Realities, and Halliday, looking at app permissions and trackers, as well as 9 privacy criteria covering areas such as camera indicators, data retention, on-device processing, and dedicated privacy documentation.

Key findings:

  • Meta requests the most permissions overall (70) and the most dangerous permissions (18), including access to read external storage and SMS and to record audio.
  • INMO Global and Solos AirGO contain the most trackers, with 6 detected in each app, while Hi Rokid is the only app with no trackers detected.
  • All 7 analyzed apps rely on cloud processing for their AI features – none runs core features such as voice, translation, or image analysis locally on the glasses.
  • 5 of 7 brands don’t specify any data retention limit.
  • Only Meta and Rokid have a confirmed response when the glasses’ recording indicator light is covered.
  • Only 3 of the 7 brands – Meta, Rokid, and Even Realities – have privacy documentation specifically written for their glasses.

The findings show that the privacy risks of smart glasses extend beyond people who may be unknowingly recorded to the people wearing the devices themselves.

Full research:

https://cybernews.com/ai-news/smart-glasses-privacy

OpenTable and Visa Extend Their Agreement in the U.S., Mexico and Canada

Posted in Commentary with tags on October 6, 2026 by itnerd

OpenTable and Visa today announced a renewed agreement across the U.S., Mexico and Canada. The next phase will broaden the Visa Dining Collection in Mexico and Canada and deliver an expanded events program, giving eligible Visa cardholders more ways to discover and book memorable dining experiences across the three countries.

The Visa Dining Collection Grows Across Canada and Mexico

The Visa Dining Collection will continue as part of a new multi-year agreement in Canada and Mexico, providing eligible Visa cardholders with exclusive access to sought-after restaurant reservations in Mexico City, Monterrey, Los Cabos and Cancun, as well as Toronto, Montreal, Vancouver, Calgary and surrounding areas.

The participating portfolio includes restaurants from MICHELIN Starred venues to local favorites and beloved culinary destinations. Existing restaurants within the Visa Dining Collection are returning to the program including Mon Lapin and Rôtisserie La Lune in Montreal, LOREA and Pargot in Mexico City and KOLI in Monterrey, with new additions coming soon.

Eligible Visa cardholders in Mexico and Canada will also have access to a new roster of exclusive dining events and experiences featuring renowned chefs and rising culinary stars. Eligible Visa Infinite cardholders world-wide traveling to Mexico or Canada will be able to book held tables and events at participating restaurants through the Visa Dining Collection, while those visiting the U.S. can access and book special events.

Events Continue in the U.S. Following Strong Demand

In addition to delivering events programming in Mexico and Canada, OpenTable and Visa are expanding their events program in the U.S. through 2029.

The expansion comes following a successful events calendar over the past two years, which saw over 80 bespoke events, the majority of which sold out. This includes Friends in Town, where chefs invited their friends to town to cook one-of-a-kind collaboration dinners, and Off the Clock, an after-hours dining experience inspired by late-night chef rituals. It also reflects a growing demand for dining experiences that go beyond the norm, which diners are seeking out more than ever. This year, 48% of Americans said they are more likely to dine at a restaurant when it’s hosting a pop-up, collaboration, or special experience.

To explore the Visa Dining Collection, visit pages for Mexico and Canada. North America events to be announced at a later date via opentable.com/visa-dining-program/events.

*Methodology

An online survey was conducted by WALR among 1527 US respondents, with quotas weighted for major cities. Fieldwork took place between September 3rd – September 9th 2025. Data has been collected adhering to MRS (Market Research Society) and ESOMAR guidelines to ensure ethical and accurate data collection.