This week’s big cybersecurity stories feel increasingly close to the day-to-day reality of customer experience teams.
What caught my attention was how varied the incidents were, but how often they came back to the same question: who or what has access to customer data and business systems, and how much control do organisations really have over that access?
We’ve had a high-profile ASOS breach involving customer communications, hundreds of vulnerabilities found in open-source software, and a growing push to give AI more responsibility for both attacking and defending systems. Microsoft is also working out how to put firmer boundaries around AI agents as they gain access to enterprise environments.
For me, that makes this week's security news particularly relevant to CX, because these are increasingly the systems sitting behind customer conversations, data and service delivery. So when something goes wrong, the security issue can quickly become a customer issue too.
A security incident can expose customer data without taking a website offline, while an AI agent can create operational risk without being compromised at all. Meanwhile, vulnerabilities buried deep in open-source software can threaten the applications supporting customer journeys even when those applications themselves appear secure.
ASOS Breach Puts Customer Communications in the Spotlight
Fashion retailer ASOS confirmed on October 6 that it was investigating a cyber incident after customers received an unauthorised push notification.
The fashion retailer said basic personal information, including names and contact details, may have been accessed. It said it did not believe payment card information or account passwords had been affected.
The incident prompted the UK's National Cyber Security Centre (NCSC) to reiterate its data breach guidance and warn customers to be alert to suspicious messages that could arrive after a cyberattack.
The NCSC advised ASOS customers to assume they were affected, even if they did not receive the unauthorised notification, and to be cautious about suspicious links in push notifications, emails and messages.
For CX teams, the incident is a useful illustration of how the customer engagement stack has become part of the security perimeter. A compromise involving a communications platform can create a phishing opportunity even where core services remain available.
Customer experience leaders often think about resilience in terms of keeping websites, apps and contact centres operational, but the incident shows why the integrity of the messages travelling through those channels also needs attention.
IBM and Red Hat Find 400+ Vulnerabilities Hiding in Open Source
IBM and Red Hat announced this week that their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.
The companies said the vulnerabilities have been found in production-grade open-source software and that fixes have been backported so enterprises could address the issues without replacing their existing software or disrupting production environments.
IBM and Red Hat also made Lightwell Clearinghouse generally available, allowing enterprise customers to submit specific open-source dependencies for priority review and remediation.
The companies warn that autonomous AI agents could combine several lower-risk weaknesses into a more serious attack, creating an awkward security equation for enterprises adopting agents. An organization may carefully control what an agent can access, yet the applications and libraries underneath those workflows can still contain exploitable weaknesses.
For customer-facing businesses, the operational consequence is significant, as open-source vulnerabilities can sit several layers beneath CRM, contact center, ecommerce and other customer systems. Fixing them quickly, while keeping those services running, becomes part of maintaining customer trust and continuity.
Anthropic Opens the Door to More Powerful Cyber AI
Anthropic expanded its Cyber Verification Program this week, creating three access tiers for security professionals seeking access to advanced cyber capabilities and reduced blocking classifiers.
The company says the program is intended to give vetted defenders greater freedom to use its models for vulnerability research and other legitimate cybersecurity work while retaining tighter restrictions on general-purpose access.
Anthropic's figures indicate why the debate is becoming harder to ignore. Through Project Glasswing, its partners identified at least 129,000 verified software vulnerabilities between April and July 2026, the company said. Anthropic's own open-source scanning identified another 5,500 between April and October, with more than 33,000 of the vulnerabilities so far rated critical or high severity.
The model developer also published results from its testing of different safeguard levels. In one tier, safeguards blocked 46 of 50 simulated cyber tasks. In a more permissive red-team tier, Claude completed 34 of 50 tasks, matching the completion rate achieved without safeguards.




