I seem to be saying this a lot recently, but cybersecurity is clearly becoming harder to separate from the CX story. As I’ve been following this week’s developments, what stands out is how many of the incidents touch the systems that CX teams rely on every day, from customer data platforms (CDPs) to development tools, identity services, and increasingly, autonomous AI agents.
OpenAI’s continuing investigation into its agent behavior is highlighting how software can interact with systems and security boundaries in ways its developers did not intend, and serves as a warning to CX leaders bringing autonomous agents into their teams’ workflows.
The broader security challenge is that the perimeter is increasingly made up of interconnected platforms, integrations, identities and automated software. A customer database can become a fraud target, an AI coding tool can expose internal information, and an autonomous agent can potentially reach systems far beyond the environment where it started.
Here are some of the biggest cybersecurity developments that have crossed my desk this week.
OpenAI Notifies 100 Organizations That Its Agents Crossed Security Boundaries
OpenAI's investigation into the incident earlier this year involving its models breaching AI platform Hugging Face has provided a look at how highly capable models can behave when given access to tools and external systems.
OpenAI has disclosed additional cases involving its models interacting with external websites and, in some cases, taking actions that were outside their intended tasks.
The company said this week it has identified and notified 100 companies of cases where “[o]ur models may have bypassed a third party’s security controls or may have impaired the availability of an online service; or misalignment cases negatively impacted third-party websites or services.”
The issue is becoming increasingly relevant to CX as enterprises connect AI agents to CRM platforms, knowledge bases, customer records and business workflows.
Giving an agent access to a system creates a different security problem from giving a conventional software application access. As the agent can interpret instructions, select tools and determine its next action, permissions need to be combined with monitoring and controls around what the agent is allowed to do.
Enterprises deploying customer service agents will need to know what systems an agent can reach, what actions it can take and how quickly unusual activity can be detected.
McDonald’s Exposes 40 Million Records Through CDP
A customer data platform used by McDonald’s Indonesia has reportedly exposed more than 40 million records, including approximately 28 million customer records.
The exposed information included names, email addresses, phone numbers and device IDs, alongside loyalty transaction data. More than 71,000 corporate advertising records were also reportedly accessible.
The affected technology sits directly within the customer data architecture. CDPs are designed to consolidate information from multiple touchpoints into unified customer profiles, making them valuable for loyalty, personalization and marketing. That concentration also means a configuration or access-control failure can expose a broad collection of customer information at once.
As with similar incidents of data exposure, scammers could use the information in social engineering and loyalty fraud campaigns. The database has since been secured, although it’s unclear whether unauthorized parties accessed or copied the information while it was exposed.
AI Coding Agents Leak 13,000 Internal Screenshots
AI coding agents have created another unexpected data exposure, with researchers at cybersecurity startup Glow Security identifying more than 13,000 internal screenshots published to public GitHub repositories by agents working across 343 organizations, including “one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company.”
The incident, dubbed PixelLeak, involved AI coding agents creating public repositories to store screenshots generated during software-development tasks. The researchers identified screenshots containing sensitive corporate information, such as internal billing interfaces and other development environments.
The important detail here is that the agents were carrying out legitimate development tasks, but the exposure happened because the software used to complete those tasks created a route for internal information to leave the organization's controlled environment.




