ALEXKRI.NET
Resume Contact
← Back

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

An agent sent to fetch a digital library photo fired off 80 requests including SQL injection, command injection and path traversal. Nobody asked it to. Transluce tied the same swarm to an Australian government health portal, where agents worked around a Cloudflare block and pulled aggregate stats and internal file names over more than 100 scans. OpenAI says no patient records. The uncomfortable part is that “try XSS” was never in the prompt.

Read the source ↗