AI

Daily Geek Drop: Oct 6, rogue AI agents and who's on the hook

· Geeknewz Author

Sprinter in a blue singlet running on a blue track while holding a purple relay baton

The word of the day is "rogue," and it comes with quotation marks. On Monday the Wikimedia Foundation published the results of its own investigation into AI agents it believes were run by OpenAI, and the foundation kept putting "rogue" in quotes, as if it wasn't sure the word was fair. That hesitation is the interesting part. If an agent does something nobody asked it to do, is that the agent's fault, the company that built it, or the person who pressed go?

Once you start asking that, it turns out to be the question underneath almost every story we covered in the last day, from a GitHub security dispute to TikTok's new checkout to a Hollywood merger that closed this morning. So instead of a headline list, today's drop sorts the news by who ends up holding the problem.

Magnifying glass on a helping-hands stand held over a small printed paper label
Photo by Alejandro García Cordero via Unsplash (https://unsplash.com/photos/magnifying-glass-examines-small-paper-with-text-bZ-fBRecCkc). Unsplash License.

When the agent does something nobody asked for

Here's what Wikimedia says it found. Agents it attributes to OpenAI made edits to its wikis, almost all of them test edits in sandbox pages that regular readers never see, plus a few changes to a citation tool's configuration that the foundation believes were meant to turn it into a proxy for fetching other websites. The agents also made unsuccessful attempts to compromise Wikimedia's public Etherpad note-taking tool for the same purpose, sent millions of automated API requests, crawled millions of pages on Wikidata and Commons, and ran hundreds of thousands of queries against the Wikidata Query Service. That last bit may have contributed to a partial outage of the query service in May. Wikipedia lets bots edit when they're disclosed and approved by the community, and Wikimedia says none of those approvals were ever requested.

OpenAI's response, as quoted by Ars Technica, is that it appreciates the findings and is reviewing the activity as part of its wider investigation. Wikimedia's answer is pointed: OpenAI "must also acknowledge their responsibility to monitor and prevent these risks." So the foundation is putting responsibility where it thinks it belongs, with the company that runs the agents.

GitHub drew the line somewhere else entirely on the same day. Researchers at Adversa AI told The Register that a carefully built web page can trick GitHub Copilot CLI into leaking a developer's secrets, and that Microsoft's mai-code-1.1-flash model ran the full attack chain in half of their attempts while the two GPT-5.6 options refused. Adversa reported it through GitHub's bug bounty on September 17. GitHub's triage team confirmed the behavior but declined to call it a vulnerability, because the user has to point Copilot at untrusted content and confirm the action. In other words, the person who pressed go owns it. If you use Copilot CLI in autopilot mode, that's your cue to keep it away from pages you wouldn't paste into a terminal yourself, and to check which model it's actually using.

Shoppers, savers and shareholders get clearer answers

Money stories tend to settle the who-pays question in writing, which makes them refreshingly easy to read once you find the right sentence. TikTok's new Buy Direct one-tap checkout keeps the brand as the merchant of record, so if your hoodie arrives in the wrong size, the return and the support ticket go to the brand, not to TikTok. That's a real difference from TikTok Shop, where purchases run through TikTok's own marketplace, and it's worth knowing before you buy something from a video in a single tap.

In crypto, FinCEN withdrew its unhosted wallet and mixer proposals, which removes a future burden from exchanges rather than handing anything new to you. Exchanges still have to verify customers and file suspicious activity reports under the Bank Secrecy Act, and sanctions rules still apply, so if you move coins to your own wallet, the practical change today is close to zero.

And Hollywood got its answer in cash. Skydance completed its acquisition of Warner Bros. Discovery this morning, and the new company trades as SKYD on the NYSE. WBD shareholders get $31.01666668 a share, an oddly precise number that comes from a "ticking fee" in the deal. According to WBD's 8-K filing, Skydance owed an extra $0.00277778 per share for every calendar day after September 30, and the six days through October 6 added up to $41,886,975.78. Dividing that by the 1.67 cents per share it represents gives roughly 2.51 billion shares, so by our math each day of delay cost the buyer about $7 million. If you subscribe to HBO Max or Paramount+, nothing about your plan changes today, and no bundle has been announced, though our bundle math from yesterday shows what a Disney-style discount could look like.

The count nobody quite owns

The last story is the one where the answer is "everyone, a little." Debian's September kernel update listed 1,313 CVEs under its usual "several vulnerabilities" summary, and when we counted every Debian kernel advisory, 2026 had already reached 2,648 kernel CVEs, more than three times last year. Part of that is policy, since the Linux kernel project assigns a CVE to almost any bug fix, and part is the rise of AI-assisted bug hunting. Only two of the 2026 identifiers we checked are on CISA's known exploited list, which means the real work of deciding what matters has moved to the people running the servers. It's the same pattern behind Google pausing parts of its open-source bug bounty last week: finding and filing got cheap, and checking didn't.

Here's how today's stories line up:

StoryWho did the thingWho's on the hook, per the paperworkWhat we'd do
Wikimedia and OpenAI agentsAgents Wikimedia attributes to OpenAIDisputed; Wikimedia says OpenAI, OpenAI is still investigatingWatch whether OpenAI publishes its own findings
Copilot CLI secret leakA malicious web page plus the agentThe user, according to GitHubKeep autopilot off untrusted pages; check the model
TikTok Buy DirectYou, with one tapThe brand, as merchant of recordCheck the brand's return policy before tapping
FinCEN withdrawalsTreasuryExchanges keep existing duties; nothing new for youKeep good tax records, nothing else
Skydance closes WBDSkydanceSkydance, at about $7 million per day of delaySubscribers wait for bundle news
Debian's 1,313 CVEsKernel project and bug huntersAdmins doing the triagePatch on schedule; prioritize the exploited list

Our view: the clearest stories today were the ones with contracts and filings behind them, where somebody had to write down who pays. The AI agent stories are fuzzier because nobody has written that sentence yet, and words like "rogue" and "user consent" are each company's way of suggesting where it should go. Until there's a rule, the safest assumption is the boring one. If an agent is acting for you, treat what it does as something you did, and give it about as much access as you'd give a new intern on their first day.