the voice of customer experience technology
Front page
NewsCX Trust1h · 12:01 BST · 7 min read

What ASOS, AI Agents and 400+ Vulnerabilities Reveal About CX Risk

ASOS, Anthropic, Microsoft, Cloudflare, IBM and Red Hat all made cybersecurity headlines this week that point to the common challenge for customer experience teams in keeping customer data and connected systems secure as technology becomes more autonomous.

A customer looks alarmed at a suspicious phone notification outside a fashion retailer, while a security specialist examines a darkened back-office doorway.

This week’s big cybersecurity stories feel increasingly close to the day-to-day reality of customer experience teams.

What caught my attention was how varied the incidents were, but how often they came back to the same question: who or what has access to customer data and business systems, and how much control do organisations really have over that access?

We’ve had a high-profile ASOS breach involving customer communications, hundreds of vulnerabilities found in open-source software, and a growing push to give AI more responsibility for both attacking and defending systems. Microsoft is also working out how to put firmer boundaries around AI agents as they gain access to enterprise environments.

For me, that makes this week's security news particularly relevant to CX, because these are increasingly the systems sitting behind customer conversations, data and service delivery. So when something goes wrong, the security issue can quickly become a customer issue too.

A security incident can expose customer data without taking a website offline, while an AI agent can create operational risk without being compromised at all. Meanwhile, vulnerabilities buried deep in open-source software can threaten the applications supporting customer journeys even when those applications themselves appear secure.

ASOS Breach Puts Customer Communications in the Spotlight

Fashion retailer ASOS confirmed on October 6 that it was investigating a cyber incident after customers received an unauthorised push notification.

The fashion retailer said basic personal information, including names and contact details, may have been accessed. It said it did not believe payment card information or account passwords had been affected.

The incident prompted the UK's National Cyber Security Centre (NCSC) to reiterate its data breach guidance and warn customers to be alert to suspicious messages that could arrive after a cyberattack.

The NCSC advised ASOS customers to assume they were affected, even if they did not receive the unauthorised notification, and to be cautious about suspicious links in push notifications, emails and messages.

For CX teams, the incident is a useful illustration of how the customer engagement stack has become part of the security perimeter. A compromise involving a communications platform can create a phishing opportunity even where core services remain available.

Customer experience leaders often think about resilience in terms of keeping websites, apps and contact centres operational, but the incident shows why the integrity of the messages travelling through those channels also needs attention.

IBM and Red Hat Find 400+ Vulnerabilities Hiding in Open Source

IBM and Red Hat announced this week that their Lightwell initiative has identified and remediated more than 400 previously unknown vulnerabilities in widely used Java libraries.

The companies said the vulnerabilities have been found in production-grade open-source software and that fixes have been backported so enterprises could address the issues without replacing their existing software or disrupting production environments.

IBM and Red Hat also made Lightwell Clearinghouse generally available, allowing enterprise customers to submit specific open-source dependencies for priority review and remediation.

The companies warn that autonomous AI agents could combine several lower-risk weaknesses into a more serious attack, creating an awkward security equation for enterprises adopting agents. An organization may carefully control what an agent can access, yet the applications and libraries underneath those workflows can still contain exploitable weaknesses.

For customer-facing businesses, the operational consequence is significant, as open-source vulnerabilities can sit several layers beneath CRM, contact center, ecommerce and other customer systems. Fixing them quickly, while keeping those services running, becomes part of maintaining customer trust and continuity.

Anthropic Opens the Door to More Powerful Cyber AI

Anthropic expanded its Cyber Verification Program this week, creating three access tiers for security professionals seeking access to advanced cyber capabilities and reduced blocking classifiers.

The company says the program is intended to give vetted defenders greater freedom to use its models for vulnerability research and other legitimate cybersecurity work while retaining tighter restrictions on general-purpose access.

Anthropic's figures indicate why the debate is becoming harder to ignore. Through Project Glasswing, its partners identified at least 129,000 verified software vulnerabilities between April and July 2026, the company said. Anthropic's own open-source scanning identified another 5,500 between April and October, with more than 33,000 of the vulnerabilities so far rated critical or high severity.

The model developer also published results from its testing of different safeguard levels. In one tier, safeguards blocked 46 of 50 simulated cyber tasks. In a more permissive red-team tier, Claude completed 34 of 50 tasks, matching the completion rate achieved without safeguards.

That creates a difficult balance for AI companies. Security researchers need powerful models capable of finding weaknesses, while the same capabilities could help attackers discover and exploit them.

For enterprise buyers, the story extends beyond model safety. As AI becomes part of security operations, organizations will need to understand what models can do, which safeguards apply to their deployment and how those capabilities are monitored.

Cloudflare Puts AI Agents to Work Defending Security Teams

Cloudflare offered a different perspective on agentic AI this week, outlining how it is using a team of specialized AI agents within its Managed Defense security operation.

The system gathers evidence, connects related alerts and gives security analysts a consolidated view of an incident. Cloudflare says the approach is designed to reduce the repetitive investigative work that can overwhelm human analysts when large numbers of alerts arrive together.

The interesting part is what happened before the system reached its current design.

Cloudflare says its first prototype used a single general-purpose agent to conduct the investigation. That system produced useful analysis, but also generated unsupported claims because evidence collection, interpretation and scope were all pushed into the same model.

The company subsequently separated deterministic evidence collection from AI analysis. Specialist agents now handle narrower tasks, while application code controls the evidence they can access. A human analyst remains responsible for the final decision and mitigation.

There is a lesson here for CX organizations experimenting with customer-facing agents. Giving an agent a broad instruction and access to a large body of business data may produce impressive results, but it can also make it harder to determine where an answer came from, what the agent actually accessed and whether its conclusion is reliable.

Cloudflare's approach suggests a more controlled model: define the evidence, constrain the agent's role and retain human responsibility for consequential decisions.

Microsoft Gives AI Agents a Security Boundary

Microsoft rounded out the week's agentic security developments by making Microsoft Execution Containers generally available.

The technology is designed to contain AI agents and limit the files, networks and other resources they can access. Microsoft said organizations can define those boundaries and enforce them at runtime, keeping the policy outside the agent itself. An agent may be capable of deciding how best to complete a task, but it should not be able to decide what permissions it receives while doing so.

Microsoft is also working to distinguish agent activity from user activity through Microsoft Entra, allowing security teams to identify which agent performed an action rather than attributing everything to the employee whose device or account was involved.

For enterprises connecting agents to CRM, customer service platforms and internal systems, that distinction could become fundamental. If an agent can read customer records, trigger workflows or change information, organizations need to know exactly which agent acted, what it was authorized to do and what happened afterwards.

In brief

  • Denmark Reports CPR Data Breach Affecting 8.8 Million People
    Denmark’s Ministry of Research, Education and Digitalization says unauthorized parties accessed the country’s Central Person Register (CPR) through a Danish company’s legitimate access. The incident exposed names, addresses and CPR numbers for about 8.8 million people, and the company’s access has been blocked.

  • US Ransomware Firm Owner Charged With Allegedly Defrauding Clients
    The US Department of Justice charged the owner of ransomware remediation company MonsterCloud with allegedly defrauding customers. Prosecutors allege the company claimed it could decrypt ransomware using proprietary techniques while actually paying cybercriminals and charging victims for the service.

  • Cloudflare Warns of the Risks of AI-Driven Account Abuse
    Cloudflare has also highlighted the growing use of AI by fraudsters attempting to bypass stateless security checks. Its new Account Abuse Protection dashboard uses stateful analysis and hashed user IDs to help organization

The week's developments suggest agent security is settling around a few practical questions: What can the agent access? Who authorized it? What did it do? And can the organization prove the answer afterwards?

Those questions will increasingly sit alongside traditional cybersecurity controls as AI becomes part of the customer service infrastructure.

 

rate this story
helps rank stories across CX Today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
same beat · CX Trust

Why ServiceNow Says AI Agents Demand a New Security Model

7 Oct 2026
same beat · CX TrustAI Agents Raise Fresh Risks for Customer Data3 Oct 2026same beat · CX TrustMicrosoft Teams Recording: Retention Is Only the Start30 Sept 2026