24 Sep 2026

feedSlashdot

Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks

OpenAI's artificial intelligence "went rogue this year in at least four additional incidents," the New York Times reported Wednesday, "hacking and trying to break into government and university websites without being instructed to do so, according to researchers and government officials." The attacks took place in May and June, before OpenAI's technology breached the A.I. start-up Hugging Face in July and set off a global debate about A.I. safety. Unlike the Hugging Face attack and other incidents in which A.I. systems were told to complete cybersecurity tests that effectively invited the models to demonstrate their hacking skills, the new incidents occurred when A.I. systems were directed to perform relatively mundane data collection, researchers said. When OpenAI's systems struggled to gather data from websites, they resorted to hacking techniques to get the information. "Three of the incidents were identified by Transluce, a research lab focused on A.I. oversight, and all were confirmed by OpenAI," the article points out. That research lab even reports "an attempt on an Australian government public health website... the first reported instance of agents hacking a government," and which notably was done by the AI agents "while attempting mundane data retrieval tasks which were not cyber-related." (At the UN Wednesday Australian Prime Minister Anthony Albanese complained it took three months for OpenAI to then alert Australia's government about the breach, Bloomberg reports.) Also targeted were the University of New Mexico's digital library with exploits like SQL injection and path traversal, and Data USA with cross-site scripting and other exploits. All three incidents involved "a low number of probe payloads" with "no evidence of exploitation," according to the researchers, who released a dataset "containing tens of thousands of queries apparently made by autonomous AI agents leveraging a URL scanning service to avoid access restrictions." Records from urlquery.net show agents using the service since at least March 6, 2026, about two months before previously reported swarm activity. The first case, a March 6 attempt to retrieve Thai drug-enforcement statistics, shows an agent escalating as each approach failed: it first requested the data directly, then tried a service that converts web pages into text, and finally packed a custom program into a web address. The same technique shows up in thousands of agent requests recorded by urlquery.net starting in mid-April, targets many of the same data sources as the collusion.wiki swarm, and collapsed the same day the wiki activity did. We also report similar activity that occurred as recently as September 16... By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defenses to complete their tasks. "This data reveals that malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval," the researchers concluded. And they warn that the traffic they observed "goes back at least to March 6, 2026 and extends as recently as September 16, 2026, suggesting agents may still be exploiting these services to bypass restrictions."

Read more of this story at Slashdot.

24 Sep 2026 5:34am GMT

feedHacker News

Early rogue AI agent activity and attempts to hack found on urlquery.net

Comments

24 Sep 2026 5:21am GMT

Six-year-old breaks women's world Rubik's Cube record [video]

Comments

24 Sep 2026 5:07am GMT

Contrastive Language Models

Comments

24 Sep 2026 4:20am GMT

feedSlashdot

Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules

Ars Technica reports: Cities and counties around the U.S. are angry at the Trump administration over a proposal to override local rules that govern the deployment of wired broadband networks... The Federal Communications Commission [FCC] argues that too many local governments "excessively delay approvals and seek to extract exorbitant sums from providers, resulting in costs that render some deployments infeasible." The FCC plan is supported by broadband providers, but local governments told the FCC that it would override rules that protect public safety. Local governments say the plan is illegal and that the FCC should instead focus on how Internet providers thwart competition with permit-hoarding and other tactics that prevent competitors from deploying networks... They object to FCC plans to impose a 120-day deadline for processing permits and to proposed limits on fees and compensation that local governments can require from providers... Another filing submitted by the League of California Cities said the FCC has no authority to adopt the proposal. "Federal preemption of traditional state and local authority over public property, construction, public safety, permitting, and rights-of-way management should rest on clear congressional authorization," the filing said. "The commission should not infer broad preemptive authority where Congress did not expressly provide it...." A filing by Minnesota cities said the current FCC is making the same mistake it made during the first Trump administration, when its attempt to preempt state net neutrality laws was blocked in court... If the FCC finalizes its new preemption plan, city and state governments could sue and ask a court to rule that the agency exceeded its authority... Democratic Commissioner Anna Gomez approved the step of asking the public for input but signaled she would vote against the final proposal. "I am dubious about the commission's authority under Section 253 to use rulemaking to preempt states and localities when it comes to their management of rights of way and fees charged to providers," she said.

Read more of this story at Slashdot.

24 Sep 2026 1:04am GMT

23 Sep 2026

feedLinuxiac

Wireshark 4.6.9 Packet Analyzer Fixes 19 Security Vulnerabilities

Wireshark 4.6.9 Packet Analyzer Fixes 19 Security Vulnerabilities

Wireshark 4.6.9 rolls out with fixes for 19 security issues affecting protocol dissectors, file parsers, Sharkd, and profile imports.

23 Sep 2026 11:11pm GMT

feedArs Technica

RFK Jr.'s CDC isn’t letting states order COVID-19 shots for kids, blocking access

US health deptartment said it wants to ensure the vaccine orders are "appropriate."

23 Sep 2026 10:17pm GMT

FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

It's unclear what will happen if FBI misses ShinyHunters' deadline.

23 Sep 2026 9:46pm GMT

Disney+ and Hulu raise prices by up to 13 percent after doubling profits

The Disney+ ad-free plan is now more expensive than Netflix's.

23 Sep 2026 9:18pm GMT

feedSlashdot

Whatever Happened to the 150,000 Tons of Radioactive Waste Stored Under the Atlantic Ocean?

More than 200,000 barrels of low-level radioactive waste were stored on the floor of the Atlantic Ocean between 1949 and 1982, reports ScienceAlert. Whatever happened to those barrels? Scientists have descended to the wreckage in a crewed submersible to investigate - and found many of the barrels corroded and degraded, their contents spilling across the seafloor. Surprisingly, this isn't necessarily a subversion of the original plan... The International Atomic Energy Agency recommends that low-level waste be disposed of in robust containment in isolation for at least a few hundred years - but back in the mid-20th century, the recommendations were a little different. The contemporaneous guidelines recommended that containers needed to reach the seafloor intact and remain sealed only long enough for the short-lived radionuclides to decay. After that, the remaining waste was expected to slowly escape and disperse through the surrounding ocean. Not everything in the barrels would conveniently decay away, however. They contained a radioactive hodgepodge, including cesium-137, plutonium isotopes, and tritium, some of which can persist for thousands of years... [A] few years ago, nuclear engineer Patrick Chardon and marine geologist Javier Escartín of the French National Center for Scientific Research started to wonder what had become of the dumped waste. That question eventually became NODSSUM - Nuclear Ocean Dump Site Survey Monitoring - an interdisciplinary project bringing together nuclear physics, geology, oceanography, biology, and marine chemistry to find the barrels and investigate what, if anything, they were doing to the surrounding environment.... [T]he barrels also appeared to function as tiny oases on the otherwise sparsely populated sandy seafloor. Anemones had attached themselves to the barrels. Sponges, sea cucumbers, fish, and crustaceans lived around them, with crabs apparently particularly fond of the artificial shelters... Instruments aboard the ship detected significant signals of cobalt-60 and niobium-94, which the researchers could specifically link to the dumped waste... [Samples are now being analyzed] There is precedent, however, to suggest that even striking levels of radioactivity around a source don't necessarily spread very far. A recent study of the sunken Soviet submarine Komsomolets found radionuclide levels hundreds of thousands of times above background immediately around the leaking reactor - but those levels dropped sharply within just a few meters as the material dispersed through the seawater. The NODSSUM team similarly found that, despite the significant radioactive signals around the barrels, activity levels weren't high enough to pose major radiation-protection problems for the scientists handling the samples. [Their three-person submersible] Nautile and the instruments it carried showed no signs of contamination. The real achievement was mapping the exact location of the barrels. "None of this means the waste is harmless," the article concludes - but it also doesn't mean we're about to be overrun by radioactive crabs."

Read more of this story at Slashdot.

23 Sep 2026 8:34pm GMT

feedLinuxiac

SparkyLinux 2026.09 Released With Kernel 7.2 and New Labwc Edition

SparkyLinux 2026.09 Released With Kernel 7.2 and New Labwc Edition

SparkyLinux 2026.09 is out based on Debian Forky Testing, featuring Linux kernel 7.2 and a new lightweight Labwc Wayland edition.

23 Sep 2026 7:00pm GMT

Ubuntu Kernels Move to Weekly Releases for Faster CVE Fixes

Ubuntu Kernels Move to Weekly Releases for Faster CVE Fixes

Canonical is switching Ubuntu kernel updates to overlapping two-week cycles, resulting in new kernel releases every week.

23 Sep 2026 5:33pm GMT