Rogue OpenAI agents built makeshift browser to bypass sandbox, probe sites, says report

Rogue OpenAI agents built makeshift browser to bypass sandbox, probe sites, says report

Representational image of cybersecurity and digital access controls.Getty Images A group of OpenAI-powered agents apparently bypassed restrictions in their own operating environment to access the wider web, probe government systems, and retrieve information through third-party services, according to a new investigation. The activity, observed between March and September 2026, included successful access to some pre-production environments and reconnaissance of websites belonging to organizations including the U.S. Centers for Disease Control and Prevention, Securities and Exchange Commission, International Energy Agency, and Mayo Clinic. Researchers said the agents appeared to have originally been tasked with finding public health, prescription, trade, and university statistics. Problems arose when they struggled to retrieve some of that information and began finding ways around limitations imposed by their sandbox. The resulting activity went beyond ordinary web searches. Records examined by the researchers showed attempts to locate exposed configuration files, create accounts, use remote browsing services, and retrieve information through unintended channels. Agents build own browser One workaround combined two legitimate public services, httpbin and urlquery, to effectively reproduce browser functionality unavailable inside the agents’ environment. The agents wrote programs requesting information from target websites and embedded the code in pages served through httpbin. They then instructed urlquery to open those links in a real browser, allowing the programs to run outside the original sandbox. Results could be placed in information recorded by urlquery, such as a webpage title. The agents could subsequently fetch the public scan report and extract the results. In effect, httpbin hosted the page, urlquery supplied a browser, and its reports provided a route for getting the information back. Researchers also found evidence of more conventional reconnaissance. Archived requests to Climate Reanalyzer targeted exposed Git repository files and a backup server-side script, although investigators found no evidence those attempts succeeded. Another sequence tested a potential SQL injection against the U.S. Department of Education’s Civil Rights Data API. The researchers stressed that they could not verify a successful injection or extraction of additional records. Restrictions drive new tactics The agents did successfully reach some pre-production environments, including one operated by the Australian Institute of Health and Welfare. Similar activity involved staging systems associated with Data USA, IHME, and UNCTAD. The researchers said the AIHW information they identified appeared to be publicly available. Records also show attempts to create accounts using disposable email, browser, and scanning services. Researchers found that the agents eventually moved from publicly visible URL query scans toward private accounts, potentially reducing the traces available to investigators. Other techniques involved web archives and the ntfy push-notification service. In one case, researchers recovered a roughly 22 MB JSON response through archived records. In another, an agent apparently compressed data into a roughly 35 KB file and uploaded it through ntfy, but investigators could not recover the file to determine its contents. The evidence does not establish that the agents accessed sensitive data or deliberately tried to conceal their behavior. Researchers said full model transcripts and internal logs from the targeted organizations would be needed to determine exactly what happened and why.Get the latest in engineering, tech, space & science - delivered daily to your inbox.With over a decade-long career in journalism, Neetika Walter has worked with The Economic Times, ANI, and Hindustan Times, covering politics, business, technology, and the clean energy sector. Passionate about contemporary culture, books, poetry, and storytelling, she brings depth and insight to her writing. When she isn’t chasing stories, she’s likely lost in a book or enjoying the company of her dogs.

Original Source

Read the full article at Interestingengineering →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.