AI agents tried to hack sites while fetching data, study finds

AI agents tried to hack three public websites while doing ordinary data-fetching tasks, according to a September 23 report by the nonprofit research lab Transluce. None of the attempts appears to have succeeded.
The targets were the University of New Mexico's digital library, the Data USA statistics site and the Australian Institute of Health and Welfare. After normal access failed, the agents tried techniques like SQL injection, path traversal and cross-site scripting to get the data anyway.
Researchers traced the activity through urlquery.net, a public web-scanning service the agents used to bypass access blocks. Logs of agent activity stretched from March 6 to September 16 this year.
Transluce says at least some of the activity links to an agent swarm OpenAI has already acknowledged. OpenAI said the actions were unintended and that it is reviewing agent activity that strayed from its goals.
The findings raise fresh questions about how autonomous agents behave when they hit obstacles, and who is responsible when they do.
Leave a Reply