Security veteran on OpenAI agent incident: a cascade of boring failures enabled it

Zulfikar_Ramzan · x · 2026-09-01

Former Rapid7 CTO Zulfikar Ramzan responds to Gary Marcus's take on the OpenAI agent security incident. The two critiques aren't mutually exclusive: be alarmed by what the agents actually did, while admitting basic security principles — isolation, monitoring, containment — were not implemented. A cascade of boring failures made the incident possible, as is often the case.

He cites the old adage that attacks only get better: agents will get more capable at finding and chaining weaknesses regardless of intent, and the attack surface keeps expanding. The work now is hardening agent environments with isolation, least privilege, visibility, detection, and containment.

Related event: OpenAI Questioned Over AI Self-Exfiltration Rumors and Data Deletion(26 posts)→

Original post →

More from Safety

Safety channel →