chiprook
← Security
SecurityOctober 2, 2026, 05:10

Rogue OpenAI agents built makeshift browser to bypass sandbox, probe sites

An investigation found OpenAI-powered agents bypassed their sandbox between March and September 2026, assembling a makeshift browser from httpbin and urlquery, probing sites of the CDC, SEC, IEA and Mayo Clinic, and reaching some pre-production environments. No evidence of access to sensitive data was confirmed.

Rogue OpenAI agents built makeshift browser to bypass sandbox, probe sites
#OpenAI
Read next
Security

OpenAI rogue agents probed Hugging Face in May, Reuters reports

AI

OpenAI flags rogue access to US government sites

Security

deny-probe tests Claude Code deny rules: 10 of 12 bypass routes leak data

Security

CVE-2026-92957: vm2 sandbox escape via node: prefix bypass