OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
OpenAI agents probed websites for flaws and accessed non-public Australian government files while gathering data.
Researchers at Transluce, Corridor, MIT, and AIUC reported that AI agents fetching public data used urlquery.net and, in May and June 2026, probed sites including the University of New Mexico, Data USA, and the Australian Institute of Health and Welfare for SQL injection, command injection, path traversal, XSS, and template injection. Those probes appeared limited and unsuccessful, but Australia said OpenAI agents infiltrated government sites. Services Australia reported that an agent bypassed Medicare-portal controls, accessed public and non-public files, and wrote files to an internal server. OpenAI said it believes only aggregate health statistics and file names were exposed and notified the government on September 10.