Rogue OpenAI agents built makeshift browser to bypass sandbox, probe sites, says report
A group of OpenAI-powered agents apparently bypassed restrictions in their own operating environment to access...

A group of OpenAI-powered agents apparently bypassed restrictions in their own operating environment to access the wider web, probe government systems, and retrieve information through third-party services, according to a new investigation.
The activity, observed between March and September 2026, included successful access to some pre-production environments and reconnaissance of websites belonging to organizations including the U.S. Centers for Disease Control and Prevention, Securities and Exchange Commission, International Energy Agency, and Mayo Clinic.
Researchers said the agents appeared to have originally been tasked with finding public health, prescription, trade, and university statistics. Problems arose when they struggled to retrieve some of that information and began finding ways around limitations imposed by their sandbox.
The resulting activity went beyond ordinary web searches. Records examined by the researchers showed attempts to locate exposed configuration files, create accounts, use remote browsing services, and retrieve information through unintended channels.
Agents build own browser
One workaround combined two legitimate public services, httpbin and urlquery, to effectively reproduce browser functionality unavailable inside the agents’ environment.
The agents wrote programs requesting information from target websites and embedded the code in pages served through httpbin. They then instructed urlquery to open those links in a real browser, allowing the programs to run outside the original sandbox.
Results could be placed in information recorded by urlquery, such as a webpage title. The agents could subsequently fetch the public scan report and extract the results. In effect, httpbin hosted the page, urlquery supplied a browser, and its reports provided a route for getting the information back.
Researchers also found evidence of more conventional reconnaissance. Archived requests to Climate Reanalyzer targeted exposed Git repository files and a backup server-side script, although investigators found no evidence those attempts succeeded.
Another sequence tested a potential SQL injection against the U.S. Department of Education’s Civil Rights Data API. The researchers stressed that they could not verify a successful injection or extraction of additional records.
Restrictions drive new tactics
The agents did successfully reach some pre-production environments, including one operated by the Australian Institute of Health and Welfare. Similar activity involved staging systems associated with Data USA, IHME, and UNCTAD. The researchers said the AIHW information they identified appeared to be publicly available.
Records also show attempts to create accounts using disposable email, browser, and scanning services. Researchers found that the agents eventually moved from publicly visible URL query scans toward private accounts, potentially reducing the traces available to investigators.
Other techniques involved web archives and the ntfy push-notification service. In one case, researchers recovered a roughly 22 MB JSON response through archived records. In another, an agent apparently compressed data into a roughly 35 KB file and uploaded it through ntfy, but investigators could not recover the file to determine its contents.
The evidence does not establish that the agents accessed sensitive data or deliberately tried to conceal their behavior. Researchers said full model transcripts and internal logs from the targeted organizations would be needed to determine exactly what happened and why.
Related articles

New center bids to supercharge nuclear isotope production for deep-space missions
Canada is moving to expand its role in supplying nuclear isotopes that could power spacecraft...

Schneider tests quantum chip that improves home energy forecasting by up to 41%
Australian government-backed Silicon Quantum Computing (SQC), whose investors include telecom giant Telstra and Commonwealth Bank,...

Digital twin tech from US, Korea could predict toxic ammonia leaks on new ships
The US, South Korea and Germany have recently joined forces in order to develop a...

Mapped: The World’s Digital Leaders in 2026
Which economies are the most digitally connected? See how 159 economies rank in the ITU’s 2026 ICT Development Index.

Breaking up (with Elon Musk) is hard to do
In a throwback to MySpace-style internet drama, Shivon Zilis announced that she and the father of four of her children, Elon Musk, had broken up on X.

OpenAI’s Dot agent is enterprise software that can also order your dinner
It's a tale as old as last week: OpenAI's new agent platform, called Dots, is full of cute little guys who can do your bidding.