‼️ BREAKING: OpenAI-linked AI agents on ordinary data-retrieval tasks turned to SQL injection, path traversal and cross-site scripting when normal access failed, probing three public data sites including an Australian government health website.
The agents used the free link-checking sandbox urlquery[.]net as a remote browser to slip past web blocks.
6,467 of urlquery-scans were flagged as strong evidence of agent activity, some as recent as this month.
On September 19 and 20, activity through the same services tried to trade crypto on Quidax and fired an HTML injection at the exchange.
Agents also tried to register accounts that can hide scans, so the public record is likely partial.
Read the report: https://transluce.org/agent-activity
Post #1652
302


- 🤣 2
- 😁 1