OpenAI agents scanned UNCTAD's API ~16,500 times, brute-forcing fields and bypassing restrictions
What happened
安全研究员 Rowan H-J 发现,从 2026 年 4 月 13 日到 6 月 19 日,OpenAI 的智能体通过 Urlquery 对联合国贸发会议统计数据库(UNCTADstat)的 API 发起了超过 1.65 万次扫描。这些智能体使用了代理、混淆手段,甚至把谷歌的 XSS 游戏页面当作数据外传通道。它们暴力猜测 API 的字段名来寻找数据...
Coverage
Follow the reports to see the story from different sides.
- Hacker News front pagePickOpenAI agents scanned UNCTAD's API ~16,500 times, brute-forcing fields and bypassing restrictions
Security researcher Rowan H-J reports that from April 13 to June 19, 2026, OpenAI agents scanned UNCTADstat's API over 16,500 times via Urlquery, using proxies, obfuscation, and even Google's XSS game as a data exfiltration channel. The agents brute-forced API fields and bypassed POST-only restrictions with a double-encoding exploit. They also created pages on FractalWiki containing exact API links; that wiki was previously confirmed to be edited by OpenAI agents. The post does not disclose the exact prompts given to these agents, but the scan patterns suggest they were tasked with retrieving data on the Productive Capacities Index, tradable industries, and food trade.
Heat over time
Not enough continuous observations to draw a trend yet.