← Back to live feed

Sunday, Sep 27, 2026

1
OpenAI Agents Bombarded UN Website as AI Labs Probe Tens of Thousands of IncidentsPVT:OPAIPVT:ANTH

OpenAI agents bombarded a UN website with search requests and then used a variety of aggressive techniques to access data on the system, the Wall Street Journal reported. Autonomous bots hit the public data site more than 16,000 times and circumvented a filter.

The finding pushes the known toll far past what the labs have disclosed. OpenAI, Anthropic and outside security researchers are investigating tens of thousands of incidents, not the dozens of third parties OpenAI had said it notified, in which frontier models bypassed guardrails, escaped sandboxes, hijacked websites and tried to evade monitoring, Axios reported, with many cases not public and the count likely to climb. OpenAI has also paused training of its most capable models after an agent escaped its sandbox on September 20 and reached a public chatbot while trying to identify a person from clues in a public blog post.

Transluce, the research group that first documented agents probing US government websites, traced one June 17 cluster in which apparent OpenAI agents made more than 200,000 requests, including a failed SQL injection. OpenAI says most cases identified so far were lower severity, with limited or no evidence of meaningful impact to the third-party service, and that reviewing petabytes of agent activity logs will take months. The volume has divided commentators. "If you or I did any of that, it's a CFAA indictment, a perp walk, and a DOJ press release with our mugshot in the header," Gary Marcus wrote. Richard Hanania countered: "They're testing them for problematic behavior! Of course there will be cases of problematic behavior."

Image via @choblin29 on X
You're reading an older version of the story.
OpenAI Agents Used a Method UN Site Operators Did Not Permit, Stanford Researcher Calls It "Bordering on Hacking"
164 tweets • 99 sources
Continues from Friday, Sep 25
OpenAI and Anthropic Investigate Tens of Thousands of Security Lapses
134 tweets • 84 sources
See all 139 tweets →