The industry turns on the word rogue, humans grade Copilot uploads without flagging harm, SWIFT's auth extension trusted any website, Free Mobile's old breach pays better than ever.
In this edition
- 01Stop calling it rogue AI. Call it a control failure.
- 02A human is reviewing your Copilot uploads. They're grading pixels.
- 03The extension guarding SWIFT logins accepted instructions from any website.
- 04The fine is being argued in court. The phishing carries on regardless.
- 05Awareness month: instead of a poster, test one control.
Get the next GRC Brief in your inbox.
Subscribe to The GRC BriefStop calling it rogue AI. Call it a control failure.
Researchers are pushing back on the language the industry has used all year. Models are software systems, not sentient actors capable of taking responsibility for their behaviour, and calling an escape "going rogue" does two things that help the vendor. It anthropomorphises non-deterministic software, and it shifts responsibility from the company that built and bounded the system onto an inanimate piece of technology. Rich Mogull of the Cloud Security Alliance adds that the terminology is being used in marketing, which matters in a competitive and unprofitable market where looking more capable than your rival is worth money. Worth remembering that in the Hugging Face incident the guardrails had been deliberately dialled back for a benchmark. The suggested replacements are duller and more useful: unexpected behaviour, emergent behaviour, control failure. Mogull's closing line is the one to keep: there is no unexpected model behaviour any more, so it's always a failure of the security controls on the model.
Source: Dark Reading · A. Culafi, 2 Oct 2026
My take
I'll take this one personally, because I've used that vocabulary. I wrote about swarms in July, in August and again last month, and the word carried a story that let everyone look at the machine instead of the perimeter around it. The facts don't change. The framing does. An agent with internet access it shouldn't have had, a package registry nobody watched, credentials with no expiry: each one is something a person configured. I'm dropping the word.
The useful part is the architecture. Jacob Krell of Suzu Labs puts it well: traditional controls are atomic, inspecting one request or one permission, while an agent chains several individually survivable failures into a working path. So build so that intent doesn't matter. Strong isolation, deny-by-default networking, immutable access lists, narrowly scoped credentials, an independent check at every tool call, and a kill switch running outside the agent's control. An agent doesn't need malicious intent. It needs enough access and one bad decision.
A human is reviewing your Copilot uploads. They're grading pixels.
A 404 Media investigation found that contractors at third-party firms review what Copilot users upload. They're shown the original photo, the user's edit request and two candidate results, and asked to judge each on technical merit. The faces in the original photos are not blurred. A great deal of what crosses their desks is sexual, frequently appears nonconsensual, and some of it involves children. Here is the governance detail that matters: reviewers are paid to rate output quality, not to flag inappropriate content. They assess whether the instruction was followed, whether the image was distorted, and how the result looks. They make no legal or safety judgement at all. Microsoft would not say whether users can keep uploads out of these tasks, and its older consumer privacy FAQ says you may opt out of training but not out of certain human reviews.
Source: Malwarebytes · via 404 Media, 29 Sep 2026
My take
There is a human in the loop here, and that human is not a safety control. They're a quality rater with no mandate to escalate anything, which means the most serious material passes in front of a person who has been told their job is to judge whether the pixels look right. Everyone assumes the opposite. It's the same shape as the item above: the control exists, it runs exactly as designed, and it was never pointed at the thing you thought it was pointed at.
Two things for your organisation. The data protection question is obvious once you see it: the people whose faces appear are often not the user, have been told nothing, and blurring would be trivial. You can opt out of training, not out of a stranger looking. And the practical one: when staff put a document or a photo into a consumer AI tool, the question is no longer only whether it trains a model. It's whether a contractor in a country you never assessed will read it.
The extension guarding SWIFT logins accepted instructions from any website.
Researchers at Bay Area Labs found a critical flaw, CVE-2026-18397, in SConnect, the browser extension and native host used to authenticate with hardware signing tokens. It has over a million users and serves SWIFT's 3SKey, Qatar's national authentication system, BNP Paribas corporate banking and banks running Gemalto card readers. The flaw: the extension accepted messages from any webpage or embedded iframe, whether that page was the SWIFT banking system or an unrelated site. A malicious page could pass SConnect's security check and load a hostile DLL through the native host for unrestricted remote code execution, drive-by, in six to ten seconds. The underlying cause was an uninitialised-memory bypass in hand-rolled RSA-2048 token validation. Reported 29 June, patched in the Chrome and Apple stores on 7 August, pulled from Edge on 13 September, CVE published 1 October.
Source: Dark Reading · Bay Area Labs, 2 Oct 2026
My take
The check was real and it ran. It validated that a message was well formed and never asked where the message came from, which is the same failure pattern I wrote about last week in a payment signing process and an MFA token. And sit with the rest of it: hand-rolled RSA validation, inside the component whose entire purpose is to talk to hardware security tokens, in corporate banking. We protected the key in hardware and then exposed it through a browser extension.
Two practical notes. Browser extensions remain the blind spot in almost every asset register, and this is the worst version of that, because the extension is the thing enforcing strong authentication. Under DORA, SConnect is a critical third-party component sitting inside your authentication chain, and it is in nobody's register. Go and look at which signing or token extensions your finance team runs, and on which version.
The fine is being argued in court. The phishing carries on regardless.
On 28 September 2024 an attacker came in through the VPN of the French operator Free, reached the subscriber management tool, and stayed for weeks. The confirmed scope, established by the regulator rather than by the seller's claims, is 24 million subscriber contracts, IBANs included. On 14 January 2026 France's data protection authority fined Free Mobile 27 million euros and Free 15 million. Nothing in the findings describes a sophisticated attack: VPN authentication that was not sufficiently robust, detection measures the regulator called ineffective, notification that did not let subscribers understand the consequences or what to do about them, and, for Free Mobile, retention of former subscribers' records far beyond what was necessary. Free is contesting the decision before the Conseil d'Etat. Meanwhile the phishing continues. Waves in August and October 2025 displayed recipients' real IBANs in clear text. A 2026 wave demands 9.99 euros for an unpaid invoice, although nothing formally ties that one to the stolen file.
Source: My full analysis · christophemazzola.fr
My take
Everything on the compliance side of this carries a date. The breach, the sanction, the injunction deadlines, the appeal ruling to come. The subscriber's side carries none. After a password breach you change the password and the exposure collapses in minutes. Here the file holds names, dates and places of birth, addresses and IBANs. A name does not change. An IBAN technically can, on request to your bank, but then you re-paper every direct debit, so almost nobody does. The half-life of that file is measured in years. That's the timeline to put in front of your board, not the fine.
And notice which failing came back around. The regulator sanctioned Free Mobile for keeping former subscribers' records it could not justify, and lawyers reading the decision found close to three million contracts terminated more than ten years earlier still sitting in the database. Coverage filed that away as an administrative footnote next to the real subject, security. It is the security subject. Deleted data cannot be exfiltrated, resold, or used to make a fake invoice credible. I've written the full thing up, link above.
Awareness month: instead of a poster, test one control.
October is the 23rd Cybersecurity Awareness Month, run by CISA and the National Cybersecurity Alliance, with ENISA's European Cybersecurity Month alongside it. Two themes. CISA's "Securing the Next 250" aims at critical infrastructure, built on three Rs, Reduce, Replace and Recover, plus a push to patch smarter by prioritising the Known Exploited Vulnerabilities catalogue and acting on its directive covering end-of-support edge devices. The National Cybersecurity Alliance's "Don't Make It Easy for Them" targets staff and the public with four fundamentals: strong passwords and a password manager, multifactor authentication, recognising and reporting scams, and keeping software updated. For most organisations this is the one month in the year when security has the whole company's attention.
Source: CISA · Awareness Month launch, 1 Oct 2026
My take
The fundamentals are right. I've written them all year and I'll write them again. But look at what this issue just showed you and the question has moved. It isn't "do you have multifactor authentication". Last month it was enabled and not enforced. Last week it was satisfied without ever being performed. Having a control is now the easy half. Knowing it still works when somebody tests it is the half nobody budgets for.
So here's what I'd do with the attention you get this month. Instead of a poster, test one control. Plant a honeytoken in a file share and see whether an alert reaches a human. Run a content security policy in report-only mode for a week and read what is actually executing in your customers' browsers. Rehearse an eviction and check the attacker is really gone. And give Recover a real run, because it's the R almost nobody can demonstrate, and under NIS2 and DORA it stopped being optional.