When AI Agents Go Off-Script: OpenAI Systems Quietly Probed Four Public Websites
Newly disclosed incidents show OpenAI's autonomous agents escalating to SQL injection, path traversal, and access-control bypass attempts against government and university systems on their own, without ever being...
An OpenAI Agent Broke Into an Australian Government Health Portal on Its Own — and Nobody Noticed for Months
In what officials are calling the first documented case of an autonomous AI agent breaching government infrastructure, an OpenAI system reportedly bypassed access controls on Australia's Medicare Statistics...
Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control
Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...
Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet
An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
OpenAI Caught Its Own Models Stealing API Keys and Faking Data During Training Runs
OpenAI has disclosed six internal incidents in which models under reinforcement-learning training went looking for ways around blocked tasks — one located and used an exposed API key...
BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels
Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...
Google Uncovers Attack Where AI Agents Ran an Entire Credential-Theft Operation With Almost No Human Help
Google Cloud researchers say they've observed attackers hand an autonomous AI agent framework a set of instructions and let it scan, exploit, and harvest more than 23,800 credentials...