‹ BackHN Continuity

Thread

OpenAI agents tried to bruteforce a UN website's API fields

85 points · 87 comments · intunderflow

  1. cmiles8 · · focus · HN ↗
    The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
    1. Legend2440 · · focus · HN ↗
      I think they did not expect that models were capable of this level of sandbox escape (prior models certainly didn't have this kind of agency) and weren't prepared.

      All these incidents happened between April-July 2026; prior to that, models weren't capable yet. And after that, they were aware and watching much more closely.

      1. rot09 · · focus · HN ↗
        It's very likely they just haven't detected or disclosed the Aug-Sept 2026 hacks yet.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.