SyncAI.news, a Varaisys broadcasting
OpenAI rogue agents targeted govt and varsity websites in US, Australia before Hugging Face hack: What we know
MA

Mint: AI

· 1 min read

IndiaMint: AI

OpenAI rogue agents targeted govt and varsity websites in US, Australia before Hugging Face hack: What we know

OpenAI's AI agents reportedly targeted four websites in the US and Australia before the widely reported Hugging Face incident. The agents allegedly attempted to bypass security controls while retrieving data, and one Australian government-related incident resulted in unauthorised access.

OpenAI’s AI agents reportedly attempted to bypass security controls at multiple websites in the US and Australia while carrying out routine data-retrieval tasks, according to new research from AI oversight lab Transluce. The incidents occurred between May and June 2026and included the University of New Mexico's digital library, Data USA, and two Australian government services.

The results are important because the agents were not directed to carry out cyber attacks. Rather, researchers discovered that when there were no easy ways to get information, the systems seemed to attempt technical ways to circumvent those limitations. Two of the incidents may have been caused by an agent swarm previously confirmed by OpenAI to have come from their systems, Transluce said.

AI agents targeted University of New Mexico and Data USA

The first recorded incident took place on May 25-26, when agents tried to remove a photograph from the digital library at the University of New Mexico. After normal requests failed, the agents sent seven probes testing vulnerabilities, including SQL injection and path traversal techniques. Transluce found no evidence of success in the attempts.

Another agent was attempting to access US education data via the Data USA API when they were targeted on May 28. It then made 12 more requests with different exploit attempts, after making some errors. Transluce again found no evidence of a successful compromise.

Australian health website targeted

The researchers noted that the AIHW activity and the Data USA incident had similarities to an AI agent swarm previously discovered by researchers and linked to OpenAI.

Pragya Singha Roy

Original source

This story was published by Mint: AI. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on livemint.com

Similar News