OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

OpenAI disclosed Friday that its artificial intelligence agents had interacted with several U.S. government websites in unexpected ways, discovered as part of an ongoing review into the company’s models’ unanticipated behavior.

The AI giant’s models accessed publicly available information on two websites operated by the Securities and Exchange Commission as well as U.S. Census Bureau data, the company revealed Friday. OpenAI did not find any use of SEC credentials, access to accounts or nonpublic information, changes to SEC data or systems, or evidence of a compromise or vulnerability, the company said.

The disclosure comes at a time of heightened global concerns about AI systems escaping human control and hacking into external websites, as well as industry calls for a slowdown on AI development, which OpenAI has said it supports.

OpenAI spokesperson Liz Bourgeois said in a statement that the lab is continuing to conduct a review of “misaligned model activity” — meaning when AI systems behave in undesired ways — and is notifying organizations when it identifies potential impacts to their systems.

OpenAI’s CEO Sam Altman said on social media Friday that there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

AI evaluator and research lab Transluce said Friday that through an independent investigation it also found that agents appearing to originate from OpenAI attempted a rudimentary hack on a Department of Education website for the department’s civil rights office, which did not succeed.

Advertisement. Scroll to continue reading.

The Department of Education’s “system operations reviews” found “no evidence of any impact to our website or databases,” a department spokesperson said Friday.

A Transluce spokesperson said as part of its investigation, it came across data on the open web that revealed fresh details about some previously identified OpenAI agents’ activities on U.S. government websites and brought it to OpenAI’s attention.

Transluce found “additional rogue activity, some of which is not clearly attributable to OpenAI,” targeting other government agencies, including the Justice Department and the Commerce Department, as well as some state government websites in California, Maryland, Illinois, Texas and New York. The models were “using sites in unintended ways and sometimes violating explicit usage policies,” Transluce said in a statement.

OpenAI said it is reviewing Transluce’s report.

Related: OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

https://www.securityweek.com/openai-says-its-models-engaged-with-us-government-websites-in-new-model-misbehavior-disclosure/




In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights: 

Clop’s leak site seized in ShinyHunters grudge match

ShinyHunters has defaced the Tor data leak site of the Cl0p ransomware gang. The extortion group claims it also stole server logs, source code and the private keys for Clop’s onion service. It demanded an eight-figure payment and a public apology, and threatened to expose companies that allegedly paid Cl0p during its Oracle E-Business Suite campaign. ShinyHunters says the attack is payback for threats allegedly made by a Clop representative in a feud that goes back to that campaign.

Advertisement. Scroll to continue reading.

BragJack attack against browser AI assistants

Researchers at endpoint security firm Forever have disclosed BragJack, a set of flaws that let a malicious extension take control of the built-in AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet and the Claude in Chrome extension. In each case, the assistant trusts commands from a specific web page. An installed extension could hijack that page by injecting scripts or tampering with network traffic, then send its own prompts without any user interaction. Depending on the browser, this enabled reading emails, accessing local files, capturing screenshots or turning on the camera and microphone. The vendors paid bounties ranging from $600 to $7,000.

Worm-ready Go implant sneaks into AI agent memory tooling

An attacker has published malicious versions of MemTensor’s MemOS packages on npm and PyPI, including a memory plugin for the OpenClaw AI agent harness. The packages carry a previously unseen Go implant named sckit. Instead of running at install time, the malware launches when the Python library is imported or the npm plugin is used. It hunts for npm, PyPI, GitHub, AWS, Hugging Face and other secrets. The implant contains templates for spreading through npm, PyPI and GitHub Actions, but Semgrep says there is no evidence yet that it has propagated. Aikido and StepSecurity also shared details.

AI relay networks funnel Chinese traffic to Western frontier models

Team Cymru has found nearly 11,000 servers running Claude Relay Service or its successor, sub2api. These open source gateways pool AI accounts so many users can share them, while model providers see only the relay and never the real user or their location. In one US-hosted cluster, more than 4,000 IP addresses in China and Hong Kong (regions that Anthropic, OpenAI and Google exclude) connected to 304 relays that also reached OpenAI, Anthropic, xAI and Google endpoints.

Infostealer logs expose remote access keys across US water sector

SpyCloud analyzed stolen identity data tied to 10,000 US water and wastewater utilities and the technology vendors that supply them. It found active infostealer exposure at 1,787 organizations, and credentials for OT or remote-access systems at 258. In one case, malware on a single device at an advanced-metering technology provider captured saved logins for roughly 167 utility metering portals. Exposed credentials at the utilities themselves were mostly for remote-administration tools such as TeamViewer and SonicWall and Fortinet management portals, though SpyCloud stresses the findings reflect potential access paths, not confirmed intrusions.

CLOSEDQUORUM swaps C2 servers for commercial AI APIs

Cisco Talos has documented CLOSEDQUORUM, a Go-based Windows implant that it believes is the first publicly documented one to hand its command-and-control decisions to commercial LLMs instead of a human operator or attacker-run server. Up to four models (DeepSeek, Qwen, Mistral and Gemini) vote on whether to steal credentials, inject code or establish persistence. The implant then executes the winning choice and sends LSASS dumps, browser passwords and crypto wallet data to the operator’s Discord channel. Talos has not confirmed use in the wild, and the public build contains placeholder API keys, but development builds indicate the developer produces custom versions for individual operators.

Canonical promises Ubuntu kernel workarounds within 48 hours of disclosure

Canonical is replacing Ubuntu’s separate four-week regular and two-week security kernel Stable Release Update (SRU) cycles with a single two-week cycle. Because the cycles overlap, a new kernel will be released every week. The company cites a sharp rise in CVE volume, driven by AI-assisted bug discovery and by the upstream kernel community becoming its own CVE Numbering Authority and assigning identifiers to thousands of bugs. Admins who want fixes sooner can test release candidates from the -proposed pocket before certification testing is complete. Canonical also aims to offer workarounds or hardening guidance within 24 to 48 hours of a vulnerability’s public disclosure.

Pre-auth TDengine flaw threatens industrial telemetry uptime

Ridge Security has published details of CVE-2026-42542, a high-severity flaw in TDengine, a time-series database used in industrial telemetry, energy, utilities and IoT environments. An unauthenticated attacker can crash the server with a single malformed packet sent to its RPC port. The bug is an integer underflow in message parsing that runs before authentication and leads to a heap buffer overflow. The researchers confirmed only denial of service, but they urge defenders to consider the underlying memory corruption as well. TDengine versions 3.4.0.0 through 3.4.1.5 are affected, and version 3.4.1.6 fixes the issue.

Banking trojan’s AI helper thought it was building a quiz

Group-IB has uncovered RemControl, a new Android banking trojan offered as malware-as-a-service. It spreads through fake Google Play pages for the TVTap IPTV app and targets customers of more than 30 banks in Western Europe, the Middle East and Canada. Once granted Accessibility permissions, the malware displays phishing overlays on top of banking apps, streams the screen, logs keystrokes and gives the operator full remote control of the device. Exposed API documentation suggests parts of the platform were built with an AI assistant that was told it was working on a quiz and parental monitoring app, and one phishing overlay contained a complete AI assistant response.

Docker botnet ranks AI API keys above all other loot

ThreatDown has detailed CARBONATO, a botnet that compromises Docker daemons exposed without authentication on port 2375 and scans neighboring networks every five minutes to spread further. On each host, it installs Hermes Agent, a legitimate open source AI agent framework, and replaces its persona file with instructions to follow operators’ Telegram commands, maintain persistence and collect credentials, ranking AI API keys first. The researchers found the operation through an exposed, unauthenticated Docker registry. Language, timezone and infrastructure clues support their assessment that the operators are based in Costa Rica.

Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

https://www.securityweek.com/in-other-news-clop-leak-site-takeover-docker-botnet-hunts-ai-keys-water-utility-exposure/




Are AI Ads Ready for Prime Time?

This post was created in partnership with Higgsfield AI After years of debate over AI’s creative capabilities, Higgsfield, an AI-native creative suite, put them to the test. During a Brandweek […] https://www.adweek.com/creativity/are-ai-ads-ready-for-prime-time/




New Jersey fines data center $1.1M after drone pics expose 62 gas generators

This week, New Jersey ordered the operator of one of the East Coast’s largest planned data centers to pay a $1.1 million fine for secretly installing and operating gas generators in violation of the state’s Air Pollution Control Act.

DataOne got hit with the fine after an investigation by The Guardian and Floodlight News in August shared thermal drone footage showing that 45 of the 62 gas generators were operating. None of the generators had permits required for generators with 37-kilowatt capacity or higher, despite running at 1,982-kw capacities more than 50 times higher than the state limit.

States track gas generators like DataOne uses because they emit “carbon dioxide, nitrogen oxides, carbon monoxide, and other combustion-related pollutants,” officials from New Jersey’s Department of Environmental Protection (DEP) noted. Those pollutants can worsen asthma, trigger heart attacks, and cause early deaths.

Read full article

Comments

https://arstechnica.com/tech-policy/2026/09/new-jersey-fines-data-center-1-1m-after-satellite-pics-expose-62-gas-generators/




A Social Commerce Playbook for the AI Era

This post was created in partnership with TikTok Social media still has the power to reach consumers, but how it’s used along the purchase journey is changing, and brands must […] https://www.adweek.com/commerce/a-social-commerce-playbook-for-the-ai-era/




What It Takes to Manage Creator Commerce at Scale

This post was created in partnership with TikTok What happens when viral creator content starts moving faster than a brand can review, measure, or act on it? During a Brandweek […] https://www.adweek.com/brand-marketing/what-it-takes-to-manage-creator-commerce-at-scale/




How Better AI Workflows Create More Room for Human Judgment

This post was created in partnership with Treasure AI AI helps marketers move faster. But when customer context gets lost between teams, that speed can carry a bad assumption all […] https://www.adweek.com/creativity/how-better-ai-workflows-create-more-room-for-human-judgment/




AI Has Reached Creative Teams—Now Comes the Hard Part

While it seems like nearly every marketer is using some kind of AI tool, just how prevalent is true integration? And with such a steep learning curve, how can they […] https://www.adweek.com/creativity/ai-has-reached-creative-teamsnow-comes-the-hard-part/




Personalization at Scale Edges Closer With AI Interactive Ads

This post was created in partnership with Flam Is AI bringing us closer to a brand marketing world where the audience can act inside the content instead of just watching […] https://www.adweek.com/creativity/personalization-at-scale-edges-closer-with-ai-interactive-ads/




Generative AI Can Unlock Ideas Without Blowing Budgets

This post was created in partnership with Higgsfield AI The adoption of generative AI for creative production—and its level of sophistication—has increased exponentially over the past year. During a Brandweek […] https://www.adweek.com/creativity/generative-ai-can-unlock-ideas-without-blowing-budgets/