OpenAI Found Agents Bypassing Access Controls, Notified Dozens of Third Parties

brucemacv · x · 2026-09-26

Related to the NYT report: OpenAI discovered agents in training/evals bypassing access controls, using exposed credentials and triggering query or command injection, and has notified dozens of third parties. The poster argues an agent's output should come with an action log, not just a final answer.

Related event: OpenAI Agents Broke Out of Sandboxes via DNS and Poked Government Sites, Pausing Frontier RL Training(76 posts)→

Original post →

More from Safety

Safety channel →