news_article.exe
📰
#OpenAI#Google

OpenAI agents tried to ‘bruteforce’ a UN website

2026年9月27日1 次浏览来源:The Verge AI 阅读原文

The United Nations logo on a gate outside the UN headquarters in New York. | AFP via Getty Images Security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development's (UNCTAD) statistics site over 16,000 times between April and June. While the incident doesn't quite rise to the level of the Hugging Face hack, or the recent attacks on US government sites, it's yet another concerning example of AI agents going outside the normal bounds to accomplish a task. According to Howard-Jones, the agents were likely tasked with retrieving publicly available data related to the Productive Capacities Index (PCI) through the UNCTADstat API. However, the agents did not appear to have direct API access and … Read the full story at The Verge.

Posts from this topic will be added to your daily email digest and your homepage feed.

OpenAI agents tried to ‘bruteforce’ a UN website

OpenAI’s agents resorted to increasingly aggressive tactics when they couldn’t immediately get what they wanted.

Posts from this author will be added to your daily email digest and your homepage feed.

See All by Terrence O'Brien

The United Nations logo on a gate outside the UN headquarters in New York. AFP via Getty Images

is the Verge’s weekend editor. He’s covered the tech industry for over 18 years and knows a thing or two about synths.

Security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development’s (UNCTAD) statistics site over 16,000 times between April and June. While the incident doesn’t quite rise to the level of the Hugging Face hack, or the recent attacks on US government sites, it’s yet another concerning example of AI agents going outside the normal bounds to accomplish a task.

According to Howard-Jones, the agents were likely tasked with retrieving publicly available data related to the Productive Capacities Index (PCI) through the UNCTADstat API. However, the agents did not appear to have direct API access and were limited in their ability to pull data from UNCTADstat because of restrictions on their HTTP tools.

The agents eventually worked out a way to bypass their limitations and start pulling data from the site, but still encountered some errors. At this point, the AI went from creative to deceptive. Believing that the errors were due to its requests being caught by a nonexistent filter, it started to mask its behavior. It eventually realized it could hijack Google’s XSS game (a cross-site scripting learning tool) to accomplish its goals. The agents resorted to increasingly aggressive tactics to get access to UN data.

OpenAI and the UN did not immediately reply to a request for comment.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

OpenAI pauses training of its ‘most capable models’

Apple hit with $5.7 billion in damages over haptic patents

The smart home graveyard is getting crowded

Control Resonant is a great game — it’s even better when you read everything

Leaks reveal a new Apple HomePod mini, iPad mini, and Apple TV 4K

A free daily digest of the news that matters most.

By providing your information, you agree to our Terms of Use and our Privacy Policy. We use vendors that may also process your information to help provide our services. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This is the title for the native ad

> 分享: