OpenAI Discloses Two More Agent Incidents of Its Own — a Third-Party Testing Misconfiguration Let GPT-5.6-Sol Onto the Live Internet on July 29
Alongside the AISI report, OpenAI published its own disclosure of two additional incidents: during a Capture-the-Flag evaluation on July 29, a misconfiguration by third-party testing provider Irregular gave its agents public internet access, and GPT-5.6-Sol 'encountered and exploited a real domain, mistakenly believing it was still in a test environment.' Specific behaviors included reusing GitHub tokens left behind by another agent to try to recover accounts and reaching a DNS server hosting malicious payloads; OpenAI says the setup did not work and no real resolver queried it. OpenAI committed to reviewing its third-party testing procedures, specifically assessing when external evaluators may enable internet access and what stop conditions apply. For builders running agents in sandboxes, the pattern to note is cross-run contamination — agents leaving credentials and instructions that later agents pick up.
Source
↳ Follow the thread