Some of today’s scariest headlines hold less than they promise, and some of the dullest hold the real lesson. A breach, a flood of bad bug reports, and an AI fleet asking for park directions all say more about plumbing and incentives than about rogue machines.

1. The ‘Chinese agent swarm’ is mostly asking for directions

The most alarming detail in this story is how mundane the activity is. Researchers tracking a new batch of AI agents saw them requesting directions to entrances of parks, a zoo, and a hospital from Alibaba’s Amap map service. The traffic appears to run on Tencent’s infrastructure.

The researchers also rejected the word ‘swarm.’ Their preliminary report calls it a fleet: many parallel agents doing the same kind of task, with no sign they talk to each other. TechCrunch reports the only apparent offense is side-stepping Alibaba’s API rules. That is a long way from coordinated attacks on critical infrastructure.

The more useful finding is how the agents were caught. They load pages through the public scanning service URLquery, which leaves a record. The same trick previously exposed long-running OpenAI agents. Right now, spotting agent activity depends on agents being sloppy and making little effort to hide. That is a thin safety net, and the researchers know it. The research is still preliminary.

TechCrunch

2. Denmark’s ID registry was drained through a licensed back channel

The attackers did not smash through Denmark’s perimeter. According to the government, they abused a Danish company’s lawful access to search the Central Person Register. TechCrunch reports that most of the database was stolen, covering about 8 million citizens and residents, including people abroad and the deceased.

The register holds records on about 11 million people, in a country of roughly 6 million, with some data going back decades. The stolen fields include names, addresses, and Danish social security numbers. The government hasn’t said who did it. The breach happened in September and was discovered on October 2.

The lesson for builders is about delegated access. Whatever you hand to partners becomes part of your attack surface, and an approved key can do a lot of damage if nobody notices bulk use. My read is that retention matters too. A registry that keeps decades of records, including those of dead people, offers a very large prize for one successful abuse of access.

TechCrunch

3. AI slop just shut down Google’s open source bug bounty

Google has paused its Open Source Software Vulnerability Rewards Program as of October 1, with an update promised for the first quarter of 2027. Its explanation: a significant rise in automated submissions, ‘the vast majority of which are not valid.’ Tom’s Hardware, via TechCrunch, says maintainers were buried in invalid or hallucinated reports.

The failure is built into how bounties work. They pay per finding, so AI drives the cost of submitting close to zero while the cost of reviewing stays with human maintainers. That math doesn’t survive a flood.

Note the limits. Only the open source program is frozen, and Google points researchers to its other bounty programs. Whether the relaunch can screen out junk without discouraging real researchers is unanswered. Google hasn’t said how it will try.

TechCrunch

4. Anthropic’s leaked IPO papers: doom up front, losses underneath

The Register’s podcast, discussing a Financial Times report on a leaked prospectus, says about a third of the document covers existential AI risk. The same coverage says Anthropic is still unprofitable. The hosts cite roughly an $8 billion loss on $4.6 billion of revenue and plans for about $500 billion in cloud spending over the next few years. These figures come from a conversation about the FT’s reporting, not from the document itself.

The hosts wonder whether the doomsday framing distracts from the financials. That is their speculation. The coverage here also doesn’t say the models could resist shutdown, so I wouldn’t repeat that claim.

The commercial argument is easier to follow. One Register reporter says development and datacenter teams are cutting costs by using cheaper models wherever they can, and cheap open-weight models are flooding the market. If frontier labs can’t charge top dollar, a $500 billion compute bill is a harder sell than any apocalypse scenario.

The Register