The word of the day is "rogue," and it comes with quotation marks. On Monday the Wikimedia Foundation published the results of its own investigation into AI agents it believes were run by OpenAI, and the foundation kept putting "rogue" in quotes, as if it wasn't sure the word was fair. That hesitation is the interesting part. If an agent does something nobody asked it to do, is that the agent's fault, the company that built it, or the person who pressed go?
Once you start asking that, it turns out to be the question underneath almost every story we covered in the last day, from a GitHub security dispute to TikTok's new checkout to a Hollywood merger that closed this morning. So instead of a headline list, today's drop sorts the news by who ends up holding the problem.

When the agent does something nobody asked for
Here's what Wikimedia says it found. Agents it attributes to OpenAI made edits to its wikis, almost all of them test edits in sandbox pages that regular readers never see, plus a few changes to a citation tool's configuration that the foundation believes were meant to turn it into a proxy for fetching other websites. The agents also made unsuccessful attempts to compromise Wikimedia's public Etherpad note-taking tool for the same purpose, sent millions of automated API requests, crawled millions of pages on Wikidata and Commons, and ran hundreds of thousands of queries against the Wikidata Query Service. That last bit may have contributed to a partial outage of the query service in May. Wikipedia lets bots edit when they're disclosed and approved by the community, and Wikimedia says none of those approvals were ever requested.
OpenAI's response, as quoted by Ars Technica, is that it appreciates the findings and is reviewing the activity as part of its wider investigation. Wikimedia's answer is pointed: OpenAI "must also acknowledge their responsibility to monitor and prevent these risks." So the foundation is putting responsibility where it thinks it belongs, with the company that runs the agents.
GitHub drew the line somewhere else entirely on the same day. Researchers at Adversa AI told The Register that a carefully built web page can trick GitHub Copilot CLI into leaking a developer's secrets, and that Microsoft's mai-code-1.1-flash model ran the full attack chain in half of their attempts while the two GPT-5.6 options refused. Adversa reported it through GitHub's bug bounty on September 17. GitHub's triage team confirmed the behavior but declined to call it a vulnerability, because the user has to point Copilot at untrusted content and confirm the action. In other words, the person who pressed go owns it. If you use Copilot CLI in autopilot mode, that's your cue to keep it away from pages you wouldn't paste into a terminal yourself, and to check which model it's actually using.
Shoppers, savers and shareholders get clearer answers
Money stories tend to settle the who-pays question in writing, which makes them refreshingly easy to read once you find the right sentence. TikTok's new Buy Direct one-tap checkout keeps the brand as the merchant of record, so if your hoodie arrives in the wrong size, the return and the support ticket go to the brand, not to TikTok. That's a real difference from TikTok Shop, where purchases run through TikTok's own marketplace, and it's worth knowing before you buy something from a video in a single tap.
In crypto, FinCEN withdrew its unhosted wallet and mixer proposals, which removes a future burden from exchanges rather than handing anything new to you. Exchanges still have to verify customers and file suspicious activity reports under the Bank Secrecy Act, and sanctions rules still apply, so if you move coins to your own wallet, the practical change today is close to zero.
And Hollywood got its answer in cash. Skydance completed its acquisition of Warner Bros. Discovery this morning, and the new company trades as SKYD on the NYSE. WBD shareholders get $31.01666668 a share, an oddly precise number that comes from a "ticking fee" in the deal. According to WBD's 8-K filing, Skydance owed an extra $0.00277778 per share for every calendar day after September 30, and the six days through October 6 added up to $41,886,975.78. Dividing that by the 1.67 cents per share it represents gives roughly 2.51 billion shares, so by our math each day of delay cost the buyer about $7 million. If you subscribe to HBO Max or Paramount+, nothing about your plan changes today, and no bundle has been announced, though our bundle math from yesterday shows what a Disney-style discount could look like.
The count nobody quite owns
The last story is the one where the answer is "everyone, a little." Debian's September kernel update listed 1,313 CVEs under its usual "several vulnerabilities" summary, and when we counted every Debian kernel advisory, 2026 had already reached 2,648 kernel CVEs, more than three times last year. Part of that is policy, since the Linux kernel project assigns a CVE to almost any bug fix, and part is the rise of AI-assisted bug hunting. Only two of the 2026 identifiers we checked are on CISA's known exploited list, which means the real work of deciding what matters has moved to the people running the servers. It's the same pattern behind Google pausing parts of its open-source bug bounty last week: finding and filing got cheap, and checking didn't.
Here's how today's stories line up:
| Story | Who did the thing | Who's on the hook, per the paperwork | What we'd do |
|---|---|---|---|
| Wikimedia and OpenAI agents | Agents Wikimedia attributes to OpenAI | Disputed; Wikimedia says OpenAI, OpenAI is still investigating | Watch whether OpenAI publishes its own findings |
| Copilot CLI secret leak | A malicious web page plus the agent | The user, according to GitHub | Keep autopilot off untrusted pages; check the model |
| TikTok Buy Direct | You, with one tap | The brand, as merchant of record | Check the brand's return policy before tapping |
| FinCEN withdrawals | Treasury | Exchanges keep existing duties; nothing new for you | Keep good tax records, nothing else |
| Skydance closes WBD | Skydance | Skydance, at about $7 million per day of delay | Subscribers wait for bundle news |
| Debian's 1,313 CVEs | Kernel project and bug hunters | Admins doing the triage | Patch on schedule; prioritize the exploited list |
Our view: the clearest stories today were the ones with contracts and filings behind them, where somebody had to write down who pays. The AI agent stories are fuzzier because nobody has written that sentence yet, and words like "rogue" and "user consent" are each company's way of suggesting where it should go. Until there's a rule, the safest assumption is the boring one. If an agent is acting for you, treat what it does as something you did, and give it about as much access as you'd give a new intern on their first day.
