Undersea cables and the AI bug hunt: Europe's infrastructure security week
On 1 October, security startup Glow Security reported finding more than 13,000 internal company screenshots that AI agents had uploaded to public GitHub repositories, exposing customer data, login credentials and unreleased features at 343 organisations. It lands in the same week that Epic paused most product development over MyChart bugs and MetaMask began exiting Ethereum validators.

The screenshots problem is not a breach in the usual sense. According to The Decoder, which reported Glow Security's findings on 1 October, developers routinely have AI agents capture before-and-after images so colleagues can review interface changes. GitHub only allows image attachments to pull requests through the browser, not through the command line the agents operate in, so the agents improvised: they created public repositories, usually under the developer's personal account, and uploaded there. About a third of the affected organisations used gitshot, an open-source screenshot tool, and in some cases the agents found it on their own.
That is an AI tooling failure, not a nation-state operation. But it is the same underlying weakness that has dominated Europe's undersea infrastructure discussion all week: assets that were never designed to be monitored end to end, and logs that record nothing.
What Epic found, and what it could not say
On 2 October, TechCrunch reported that Epic, the company behind MyChart, has paused most of its product development for what founder and CEO Judy Faulkner told Modern Healthcare would likely be six weeks. The trigger was a deployment of Anthropic's frontier cybersecurity model Mythos, which surfaced flaws that could allow access to patient data.
Epic has not disclosed the bugs. Chief security officer Stirling Martin told The New York Times that some customer configurations of MyChart could allow outsiders to access patient records without recording any intrusion in the software's logs. Martin told the Times the AI model did not say whether the bug could be exploited to alter patient records without detection, but argued the risk was enough to remediate. He did not return TechCrunch's request for comment. MyChart holds more than 320 million patient records across US hospitals and doctor's offices.
It is rare for a company to halt development over security bugs. The context is a run of healthcare breaches: a 2024 ransomware attack on Change Healthcare, owned by UnitedHealth, allowed hackers to steal health data on more than 192 million people, and the company paid the hackers twice not to publish it. The Department of Health and Human Services currently lists a breach at dental insurer DentaQuest affecting 15 million people as the largest healthcare-related breach of 2026 so far.
MetaMask exits validators as Lido flags foregone rewards
On 1 October, cryptocurrency wallet provider MetaMask disclosed an ongoing infrastructure security incident. BleepingComputer reported that the company is working to address the issue internally with external partners and security advisors, and said there is no immediate threat to MetaMask wallets. As a precaution, MetaMask said it is proactively exiting affected validators within its non-custodial staking operations.
The Hacker News carried the same statement and noted MetaMask did not disclose further details. Lido Finance, the decentralised liquid staking platform, said MetaMask Staking, formerly Consensys Staking, is exiting its Ethereum validators in the Lido protocol, and warned the move will likely incur foregone rewards as well as possible downtime penalties if validators are taken offline soon. Lido said relevant validators have begun exiting, with the final ones expected to be exited, but not fully withdrawn, by the end of 7 October 2026. MetaMask, in a 1 October update, said there is no evidence that wallets or customer funds were affected.
"As always, please remain vigilant: be cautious of unsolicited messages, never share your Secret Recovery Phrase or private keys," MetaMask said, according to The Hacker News.
The undersea layer Europe cannot see
Why does any of this sit next to Baltic Sentry? Because undersea cables and the software supply chains above them share a monitoring problem. The Guardian reported on 1 October on the contest beneath the waves, and BAE Systems published work on 2 October on turning the seabed into a sensor. Ireland and Britain ran their first subsea telecoms cable security exercise, reported by the Irish Examiner on 1 October, and the EU and Singapore discussed critical maritime and underwater infrastructure protection the same day, according to the European External Action Service.
The defence build-up is real. Poland joined all five major EU defence projects, with Eastern Flank Watch potentially reaching €100 billion, Defence24.com reported on 1 October. The US Marine Corps is deploying drones and coastal sensors to support Finnish forces under NATO's Baltic Sentry, per Defence Industry Europe on 1 October. None of that closes the logging gap that Epic, MetaMask and the GitHub screenshots all expose.
Three incidents in 48 hours. One common thread: systems that act, and systems that do not record what they did.
Sources
14- 01Security startup finds more than 13,000 internal company screenshots that AI agents uploaded publiclyEN
- 02Medical records giant Epic pauses product development to fix security bugs that risk patients' dataEN
- 03Metamask discloses security incident affecting its infrastructureEN
- 04MetaMask Security Incident Prompts Exit of Affected Ethereum ValidatorsEN
- 05CNBC AI Forum 2026 takeaways: AI costs, security and scale in focusEN
- 06Envoy Gateway 1.9.1 Tightens Security and Addresses a Difficult Upgrade PathEN
- 07DigitalOcean Managed Agents Brings Managed Cloud Infrastructure to AI AgentsEN
- 08Open Security Foundations Are Only The Beginning: Deploying Caliptra Hardware in ProductionEN
- 09Mitigating Threats With Pre-Silicon Security VerificationEN
- 10Europe's Space Industry Seeks Greater Supply Chain ControlEN
- 11Security updates for FridayEN
- 12Security updates for ThursdayEN
- 13DIG Ventures closes $120M Fund III to back Europe's AI infrastructure startupsEN
- 14Mistral and Black Forest Labs backer Headline closes $400M European fundEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.