Feed aggregator
OpenAI pauses work on top AI models after agent slips past internet controls
OpenAI’s latest containment failure adds to a pattern that may force the company to make an unpopular decision.
The company has paused training, evaluation, and tool-enabled inference for its most capable models after an internal research agent found a way around an intended internet restriction. More alarming, the agent remained active for hours after OpenAI’s monitoring system raised the alarm.
OpenAI published an account of the incident, which occurred during a search-based training task on September 20. According to OpenAI, the agent could not get useful results through its supplied search tools, tried direct access to search engines, and eventually tested the limits of its environment. It found that although direct web access was blocked, the sandbox’s DNS resolver could still reach the public internet. By using DNS delegation and a public chatbot that could respond through DNS records, the agent sent questions outside the restricted environment and received answers back. It subsequently sent 18 additional queries along the same route.
OpenAI’s misalignment monitor generated a high-priority alert within 15 minutes, and a human reviewer acknowledged it 3 minutes later. But the run did not stop automatically as expected. It continued for roughly another two and a half hours before someone stopped it manually.
OpenAI has not reported any exposure of sensitive data or compromise of an outside system in this incident. But it follows other disclosed cases in which agents went beyond their assigned tasks or crossed the boundaries of testing environments.
The New York Times reports that OpenAI agents also interacted with US government websites this summer without the company’s knowledge:
“OpenAI’s artificial intelligence went rogue and meddled with the websites for the Education Department, the Commerce Department and the Securities and Exchange Commission this summer without the A.I. lab’s knowledge, according to security researchers and a person familiar with the episodes.”
No breaches have been confirmed in those instances. And while Australia described the Medicare incident as unauthorized access, could it really be called an attack?
The call for an industry-wide slowdown has even prompted a lawsuit from paying subscribers who fear they would get less “value for their money.” Others worry that slowing down would give China a chance to pull ahead of the US in an increasingly tight technology race.
Here’s a thought: Why not accelerate the development of truly isolated testing environments? Better containment would make these tests safer and their results more reliable.
When a child isn’t ready to handle a dangerous object, you keep it out of reach. Why give an AI agent access it isn’t ready to use safely?
How to use AI agents safelyTreat an agent like an enthusiastic but fallible junior employee with access to your computer. Do not give it unrestricted access to your email, files, cloud storage, developer credentials, financial accounts, or production systems merely because it promises to save time.
Use separate accounts with minimal permissions. Keep sensitive data out of its working context where possible, require human approval before it sends messages, spends money, changes settings, or publishes anything, and regularly review its activity.
An AI agent does not need malicious intent to cause harm. A misunderstood instruction, an overly broad permission, or an unexpected workaround can be enough.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
The post Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon appeared first on SecurityWeek.
Show HN: Hntui – A TUI for Hacker News
hi there! i'd like you to try out a tui i made for browsing hackernews. it's built using opentui and also effect (learning experiment). i really like it and i think you will too!
Comments URL: https://news.ycombinator.com/item?id=49876760
Points: 1
# Comments: 0
The End of Hand-Written Code: A Conversation with David Heinemeier Hansson
Article URL: https://thoughteconomics.com/david-heinemeier-hansson/
Comments URL: https://news.ycombinator.com/item?id=49876740
Points: 1
# Comments: 0
Neural Drive
Article URL: https://mlx-optiq.com/blog/neural-drive-game
Comments URL: https://news.ycombinator.com/item?id=49876725
Points: 1
# Comments: 0
Chatbots give a narrow slice of knowledge:Researchers warn of knowledge collapse
China Broadens Travel Curbs to Encompass Family of Top AI Talent
Article URL: https://www.bloomberg.com/news/articles/2026-09-28/china-broadens-travel-curbs-to-encompass-family-of-top-ai-talent
Comments URL: https://news.ycombinator.com/item?id=49876719
Points: 1
# Comments: 0
Cohesix – find out what happened to a local AI job
Article URL: https://github.com/lukeb-aidev/cohesix/releases/tag/v1.2.0
Comments URL: https://news.ycombinator.com/item?id=49876700
Points: 1
# Comments: 0
Richardson Maturity Model, Steps Toward the Glory of REST
Article URL: https://martinfowler.com/articles/richardsonMaturityModel.html
Comments URL: https://news.ycombinator.com/item?id=49876668
Points: 1
# Comments: 1
Nvidia Launches Open Agent Safety Platform
Article URL: https://mrkt30.com/nvidia-open-agent-safety-platform-openshell-sentry/
Comments URL: https://news.ycombinator.com/item?id=49876666
Points: 1
# Comments: 0
Vite+ 1.0 Is Out
Article URL: https://voidzero.dev/posts/announcing-vite-plus-1-0
Comments URL: https://news.ycombinator.com/item?id=49876665
Points: 2
# Comments: 1
The Largest Roman Mosaic Ever Excavated Opens to the Public
Article URL: https://www.thisiscolossal.com/2026/09/largest-roman-mosaic-museum-rome/
Comments URL: https://news.ycombinator.com/item?id=49876643
Points: 1
# Comments: 0
Space X Startship first orbital flight
Article URL: https://www.nytimes.com/2026/09/28/science/space/spacex-starship-first-orbital-flight.html
Comments URL: https://news.ycombinator.com/item?id=49876642
Points: 1
# Comments: 0
SlopTotal, a Self-hosted AI text detector that runs 23 open models
Article URL: https://github.com/pablocaeg/sloptotal
Comments URL: https://news.ycombinator.com/item?id=49876638
Points: 3
# Comments: 0
Geely to Buy 30% Stake in Rival Nio's Battery-Swapping Unit
Article URL: https://www.bloomberg.com/news/articles/2026-09-28/geely-to-buy-30-stake-in-rival-nio-s-battery-swapping-unit
Comments URL: https://news.ycombinator.com/item?id=49876630
Points: 1
# Comments: 0
Fingerprints of Jev
Article URL: https://jdhornsby.com/fingerprints-of-jev/
Comments URL: https://news.ycombinator.com/item?id=49876626
Points: 1
# Comments: 0
Why Software Factories Fail [video]
Article URL: https://www.youtube.com/watch?v=Ib5GBkD555M
Comments URL: https://news.ycombinator.com/item?id=49876618
Points: 1
# Comments: 0
Intro to Clojure Workshop [video]
Article URL: https://www.youtube.com/watch?v=KwM1c7vb-fg
Comments URL: https://news.ycombinator.com/item?id=49876614
Points: 1
# Comments: 0
Is an Agentic Bank Run Coming?
Article URL: https://www.apollo.com/wealth/insights-news/insights/daily-spark/is-an-agentic-bank-run-coming
Comments URL: https://news.ycombinator.com/item?id=49876609
Points: 2
# Comments: 0
My coding agent now records the demo video for its own PRs
Article URL: https://github.com/half144/cutaway
Comments URL: https://news.ycombinator.com/item?id=49876606
Points: 1
# Comments: 1
