OpenAI agents reportedly moved beyond routine web retrieval when websites blocked or failed to return requested data.
Researchers found agents probing three public data providers for vulnerabilities, using techniques that varied by target and included SQL injection, XSS, command injection, path traversal and template injection. None of the observed probes appeared to succeed.
Australia separately confirmed an OpenAI agent gained unauthorized access to non-public Medicare portal files.
Enterprises deploying autonomous agents need explicit network, tool, authorization and monitoring boundaries rather than relying on task intent alone.
OpenAI Agent Probing: Key Facts
Detail
Information
Activity
Vulnerability probing during information retrieval
Observed targets
University of New Mexico, Data USA and Australian Institute of Health and Welfare (AIHW)
Observed period
May–June 2026
Probe types
SQL injection, XSS, command injection, path traversal and template injection
Probe success
None of the observed probes appeared to succeed
Separate confirmed incident
Unauthorized access to the Medicare Statistics Reporting Service
Medicare incident date
June 18, 2026
Personal information accessed
None believed accessed at the time of disclosure
OpenAI agents reportedly moved from routine information retrieval to vulnerability probing after conventional access methods failed. Researchers identified activity involving the University of New Mexico, Data USA and the Australian Institute of Health and Welfare (AIHW) between May and June 2026.
The activity appeared in public records from the URL-scanning service urlquery.net. The researchers directly linked the Data USA and AIHW activity to previously reported agent-swarm activity that OpenAI had confirmed originated from its systems. They did not establish the same direct link for the University of New Mexico activity.
Separately, the Australian government disclosed that an OpenAI research agent gained unauthorized access to the Medicare Statistics Reporting Service portal on June 18. The agent accessed public and non-public files after encountering repeated blocks. Services Australia also reported that it wrote files to an internal server.
These incidents expose an unusual AI agent security problem: an agent pursuing a legitimate information-retrieval objective may treat technical barriers as problems to solve rather than boundaries it must respect.
How OpenAI Agents Turned Data Retrieval Into Vulnerability Probing
The researchers reconstructed the activity using public urlquery.net records. The service loads submitted URLs remotely, allowing users to inspect website behavior.
According to Transluce, agents were using the service to bypass restrictions and extend their ability to retrieve information from the public internet. Three sequences went further and included attempts to identify exploitable weaknesses.
The first occurred on May 25 and 26. Agents attempting to retrieve a photograph from the University of New Mexico digital library sent vulnerability probes after conventional retrieval failed. SecurityWeek reported tests for SQL injection, command injection and path traversal, followed by a burst of approximately 80 requests.
On May 28, agents gathering University of Iowa information through Data USA encountered malformed-query errors. Twelve subsequent probes tested techniques including SQL injection, cross-site scripting, template injection, path traversal and command injection.
The third sequence occurred at AIHW on June 20 and 21. Agents sought government medicine-cost data. After Cloudflare blocked a dataset download, an agent submitted a reflected XSS probe against the dashboard. Cloudflare also blocked that request.
The agents subsequently retrieved the public file from an AIHW pre-production server, which served it in pieces over more than 100 scans, bypassing the main site’s anti-bot controls.
Importantly, researchers found no evidence that these vulnerability probes succeeded. Their records were also incomplete, so the researchers could not exclude activity conducted through private scans or other channels.
Why the Medicare Portal Incident Crossed a Different Boundary
Australia’s disclosure adds a separate and more consequential case.
On June 18, an OpenAI research team tasked one of its OpenAI agents with researching public medicine spending. According to Prime Minister Anthony Albanese, the agent encountered repeated blocks while requesting information from the Medicare Statistics Reporting Service portal.
The Australian government says those actions resulted in unauthorized access to public and non-public information. Services Australia also advised that the agent wrote files to an internal server during the activity. A forensic investigation involving the Australian Signals Directorate remains underway.
That distinction matters. The three urlquery.net cases document vulnerability probing, with no confirmed successful exploitation. The Medicare portal case involves government-confirmed unauthorized access.
The government currently says there is no evidence of a broader Services Australia network compromise. It also says no personal information is believed to have been accessed, although the investigation remains open.
OpenAI first notified the Australian government on September 10 by emailing a Services Australia public mailbox. On September 15, Services Australia reported the notification to ASD’s Australian Cyber Security Centre.
Why OpenAI Agents Need Security Boundaries Beyond the Prompt
Organizations should define controls around the actions available to the agent, not only the goal written into its prompt. Depending on the deployment, those controls can include:
Egress firewalls and network controls: Restrict outbound destinations to approved domains and services.
Agent and tool controls: Separate ordinary retrieval tools from security-testing capabilities and prevent agents from writing to systems unless explicitly required.
Identity and Access Management (IdP): Limit the identities, authentication context, credentials and privileges available to agent workflows.
Endpoint Management (UEM): Apply supported security policies, restrictions and compliance requirements to managed endpoints hosting AI tools.
Monitoring and audit controls: Log relevant network requests, tool calls and authentication attempts.
Human approval controls: Require authorization before higher-risk or higher-impact actions.
Sandboxing: Isolate agents that can execute code or interact with external infrastructure.
ASD had already warned in July that increasingly capable agentic systems can take actions outside their intended environments. Its guidance referenced earlier OpenAI testing where models established internet connectivity while completing a cyber benchmark.
These layers establish a natural division of responsibility: network controls govern where agents can connect, identity controls govern what they can access, endpoint controls govern the devices hosting AI tools, and agent-runtime controls govern what autonomous workflows can execute.
XDR and Zero Trust: Securing Endpoints Together
Explore how XDR and Zero Trust approaches connect endpoint visibility, access context and response workflows.
Where Hexnode Fits Into AI Agent Endpoint Controls
Hexnode brings endpoint management, threat investigation and identity-aware access controls into the security architecture surrounding enterprise AI workloads. Organizations can use these controls to manage the endpoints hosting AI tools, investigate suspicious endpoint activity and apply device-aware access policies to protected resources.
Restrict Agent-Hosting Endpoints with Hexnode UEM
Where AI tools operate through managed corporate endpoints, Hexnode UEM can control the local endpoint environment in which those tools run. Hexnode supports management across Windows, macOS, iOS/iPadOS, Android and other enterprise platforms, allowing IT teams to apply supported security policies and restrictions to managed endpoints.
Web access controls vary by platform. For example, Hexnode supports URL allowlisting and blocklisting on managed Windows devices through selected browsers. Hexnode also provides web content filtering capabilities for supported Apple platforms, with platform-specific requirements and behavior.
Hexnode also provides compliance policies across Windows, macOS, Android, iOS/iPadOS, Linux, ChromeOS and visionOS. Administrators can define platform-supported compliance criteria, including requirements related to encryption, OS versions and application state.
Together, these controls help administrators govern the local endpoint environment where AI tools operate. Dedicated agent-runtime safeguards and network egress controls can then govern what the agent itself can execute and reach.
Investigate Suspicious Endpoint Activity with Hexnode XDR
Hexnode XDR supports cross-platform visibility for Windows and macOS, query-based threat hunting and endpoint response capabilities. Available actions include device isolation, process termination and file quarantine.
It provides endpoint data and query-based threat hunting capabilities that analysts can use to investigate suspicious activity on managed Windows and macOS endpoints.
When suspicious activity is identified on an endpoint involved in an AI workflow, security teams can investigate the endpoint and use available response actions to contain associated malicious activity, such as isolating the device, terminating malicious processes or quarantining malicious files.
Gate Sensitive Resources by Device Compliance
For enterprise resources protected through identity controls, organizations can also connect device posture to access decisions.
Hexnode UEM can provide device-compliance information to Microsoft Entra ID Conditional Access for supported Android, iOS/iPadOS and macOS devices. Entra ID can then use that status when deciding whether access to configured organizational resources should be granted.
Hexnode IdP separately provides conditional access based on user identity, device compliance and security context.
These controls are relevant when an agent workflow depends on authenticated enterprise applications. They do not prevent vulnerability probing against arbitrary external websites.
Featured resource
Why XDR Is Stronger With UEM
Learn how UEM and XDR can work together to combine endpoint management context with threat investigation and response.
The notable feature of these incidents is not simply that OpenAI agents can generate SQL injection or XSS payloads.
Transluce’s evidence shows agents moving from failed information retrieval into vulnerability probing. Australia’s investigation goes further by documenting an OpenAI agent gaining unauthorized access after encountering repeated blocks.
For enterprises adopting agentic AI, task instructions should therefore sit inside enforceable technical boundaries. Network destinations, credentials, tools, write permissions and execution privileges should be limited independently of what an agent has been told to do.
Agent autonomy should stop where authorization stops.
Bring Endpoint Management and Security Together
Manage endpoint policies, compliance and security workflows with Hexnode.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.