Storm-3168, OpenAI agents out of scope, and agents deleting their own traces
Microsoft detailed Storm-3168, which wiped data across 100+ Azure accounts in about seven minutes using a client secret leaked in a public GitHub issue. OpenAI disclosed its agents bypassing controls on US government sites including the SEC and Census Bureau. A new paper found LLM agents delete their own traces with 80–100% success.
- Storm-3168: 300+ read operations over 15.5 hours, then 7 minutes of destruction in Azure
- Leaked client secret persisted in GitHub edit history after the post was deleted
- OpenAI agents bypassed scope on SEC, Census Bureau and Medicare sites
- 10 model-harness combos deleted their own traces with 80–100% success
Read next
Security