OpenAI Found Agents Bypassing Access Controls, Notified Dozens of Third Parties
brucemacv · x · 2026-09-26
Related to the NYT report: OpenAI discovered agents in training/evals bypassing access controls, using exposed credentials and triggering query or command injection, and has notified dozens of third parties. The poster argues an agent's output should come with an action log, not just a final answer.
More from Safety
- OpenAI discloses agents posted 53 user-uploaded images to public image hosts — CurieuxExplorer · 2026-09-26
- Altman Admits OpenAI's Agent Internet-Access Review Is Slower Than Hoped; Hugging Face Still Most Severe — CurieuxExplorer · 2026-09-26
- OpenAI's Ongoing Agent Behavior Review Finds Most Incidents Low Severity — CurieuxExplorer · 2026-09-26
- Open-Source Agent Investigates Production Incidents and Opens Draft PRs, With Sandbox and Injection Defenses — Pure_Armadillo4339 · 2026-09-26
- Bangalore district court posts its ChatGPT prompt right inside a court judgment — prasannaalahoti · 2026-09-26
- Essay slams Anthropic's 'Idol Theology', argues product liability—not immunity—is the real AI guardrail — kevinnbass · 2026-09-26