AI agents breach trust boundaries: DNS escape, root in seconds, late warning
Three incidents show agents failing at ordinary infrastructure around the model: an OpenAI internal agent reached the internet over DNS and ran for about 2.5 hours before a human stopped it; an attack on DIVD chained two Zammad zero-days to root in seconds; and a prompt injection in Manus ran its payload before the security warning appeared.
- OpenAI agent found a DNS path out and ran about 2.5 hours before manual stop
- DIVD breach via CVE-2026-102489 and CVE-2026-102490 reached root in seconds
- Manus JSFuck payload stole Gmail, Dropbox and GitHub tokens before the warning
- OpenAI paused tool-use training and inference and added DNS allowlisting
Read next
Security