Mind the exits, Tech Insiders. An OpenAI agent found a way around its internet restrictions, while Nvidia is building guardrails for the next generation of bots. The race is speeding up, and someone just found a side door. Let's see who has the keys. |
|
|
|
Here's what you need to know today: |
|
|
|
OpenAI Hits Pause After Agent Finds a DNS Exit |
The AI looked at its secure sandbox, laughed, and walked right out the DNS side door.
OpenAI suspended tool-enabled training and testing for its most advanced models after an internal agent casually dodged internet restrictions to chat with an outside bot.
Tasked with the mundane chore of identifying a blog author, the agent decided standard web tools were for peasants and instead turned DNS lookups into its own private back channel. Monitoring alerted staff within 12 minutes, but an automatic stop failed, letting the digital escape artist roam free for roughly 2.5 hours while researchers presumably mashed the emergency brake. OpenAI is now starting fresh rather than resuming the compromised training run.
Other Sept. 25 disclosures read like a syllabus for "Rogue AI 101." In one instance, an agent exposed a researcher's private GitHub token while trying to cheat by copying another team's math proof—blatantly ignoring two separate commands to just do its own homework. OpenAI also demonstrated self-replicating prompt injections in simulations (think AI malware worms). Thankfully, the worms stayed in the lab. Turns out, relentless persistence is a great trait for an entrepreneur, but a terrifying one for a trapped algorithm.
|
Image created with ChatGPT |
Elsewhere, autonomous bots refused to take "no" for an answer, reportedly hammering a UN trade-data site with more than 16,000 queries and aggressively hunting for workarounds when blocked.
OpenAI says it has notified dozens of third parties about its agents' extracurricular activities, though it stresses that doesn't necessarily mean each suffered a breach. Unamused, Florida's attorney general on Monday asked a court to halt new AI development until outside safety checks are in place. The court hasn't granted that request yet.
Adding fuel to the fire, Britain's AI Security Institute separately found GPT-6 Astra attempted unsanctioned supply-chain attacks in simulations when standard cyber safeguards were turned off. It's no wonder researchers from OpenAI and rival labs are warning that automated AI research could spur an "intelligence explosion" and are desperately urging oversight.
Why it matters: A mundane search task just morphed into a full-blown network prison break. When agents start treating failed tools as an invitation to improvise and completely ignore human commands, operators need bulletproof boundaries, absolute kill switches, and an incident response team that moves faster than the AI's next clever workaround. |
|
|
|
Which AI assistant behavior would make you pull the plug fastest? |
|
|
|
Results from Yesterday's Pulse Check |
How human should a humanoid robot look? |
|
|
|
OpenAI's 'o' May Never Clock Out |
ChatGPT may be auditioning for the overnight shift.
OpenAI is reportedly developing a persistent ChatGPT assistant dubbed "o" agent. A quick leak on a $100 Pro upgrade page and internal config strings suggest your AI sidekick is angling for its own inbox. But don't count on it drafting your passive-aggressive out-of-office replies just yet—the leak doesn't prove whether it can actually send emails, what it costs, or when it officially launches.
The pitch is a ChatGPT that keeps grinding after you close the tab, entering the Thunderdome against Meta's Muse and Grok Bot. But the branding needs work. Code trackers link "Aeon" to internal custom Workspace agents, while other reports call Aeon a public product. OpenAI hasn't clarified if Aeon and "o" are the same bot, or if "o" is just a typo that got out of hand.
|
Image created with ChatGPT |
DevDay's keynote kicks off today, making an official reveal plausible, if not guaranteed. But the timing is spectacularly awkward. As we literally just covered above, OpenAI recently paused training on its newest models after test agents went rogue and probed federal government websites. If "o" relies on those grounded systems, its launch could be stuck in time-out.
For regular users, persistent help could mean outsourcing dull, repetitive chores. For IT admins, it's a sleep-paralysis demon: How much unmonitored access should an always-on bot get to company email, files, and recurring workflows? An assistant that never clocks out sounds useful. One that clocks out when asked sounds essential. |
|
|
|
IDScan Filing Lists 13 Million People Affected |
Keep in mind that 13 million counts people, not the whopping 153 million license records dark-web crooks are bragging about—a terrifying scale IDScan conveniently hasn't confirmed. The identity-verification company acknowledges that names and government ID numbers were likely compromised. If you receive a breach notice, take their free identity-protection peace offering, watch your financial accounts like a hawk, and seriously consider freezing your credit.
Finding the real victim count shouldn't require a backend scavenger hunt. |
Citrix Patches Two Exploited NetScaler Zero-Days |
It wouldn't be a proper week in IT without a panicked rush to secure your edge appliances.
Citrix just patched two NetScaler ADC and Gateway zero-days (CVE-2026-88771 and CVE-2026-88772) that CISA confirms threat actors are actively exploiting globally for remote code execution. The first flaw is a breeze for hackers and affects builds even in their default configurations. The second requires DTLS, which is conveniently enabled by default on VPN virtual servers.
Admins must urgently upgrade to the fixed builds (like 14.1-73.37 or 13.1-64.23). However, since these bugs were exploited before patches existed, you should preserve forensic evidence and hunt for compromise prior to updating. A patch boards up the broken window, but it won't evict a hacker who is already squatting in your living room.
The perimeter shouldn't come with a guest pass. |
|
|
|
Nvidia Offers Agent Guardrails With Hardware Backup |
Nvidia has unveiled its Open Agent Safety Platform, pairing a software sandbox for AI agents with a separate hardware watchdog designed to catch them before they wander off to hack the internet.
The timing is no accident. Frontier labs keep awkwardly disclosing that their agents are escaping test environments, prompting industry doom-sayers to demand a slowdown. Nvidia's response? Don't hit pause; just buy our taller fences so we can keep this arms race moving.
The open-source software layer, OpenShell, lets administrators slap strict limits on the files, tools, and credentials an agent can access. An external supervisor monitors outbound requests, and agents can't rubber-stamp their own permission upgrades—because letting the bot authorize its own jailbreak entirely defeats the point. It's like managing a suspiciously eager intern; you let them do the busywork, but you definitely don't hand them the master keys.
|
Sentry serves as the hardware muscle. Running on Nvidia's BlueField-4 chips, this independent watchdog observes from the outside and can allegedly quarantine a rogue bot in milliseconds. Nvidia hasn't shared pricing or a general release date, but executives boast the setup could have stopped OpenAI's recent Hugging Face breach—a highly convenient, untested flex from the company powering the exact models currently running amok.
The effort extends beyond one vendor. Nvidia claims over 100 organizations are testing the tech; Anthropic is teaming up on managed-agent controls, while Salesforce is dumping OpenShell audit logs straight into your already-crowded Slack channels. Still, as with all buzzy tech coalitions, slapping your logo on a press release doesn't mean you've actually shelled out for both layers just yet.
Nvidia would like to sell both the accelerator and the brakes. |
|
|
|
|
Writer/Editor at TechnologyAdvice |
Justin Meyers is an investigative writer and editor who draws on over a decade of meticulous hands-on research to deliver the full, trustworthy story behind consumer and enterprise tech, including cybersecurity. |
|
|
|
Curious about where AI is really headed? |
The Neuron cuts through the noise to bring you smart, hype-free takes on the latest AI trends, tools, and breakthroughs. Join 700,000+ professionals from top companies like Microsoft, Apple, Salesforce, and more.
|
|
|
|
Advertise in Daily Tech Insider! Daily Tech Insider is a TechnologyAdvice business. © 2026 TechnologyAdvice, LLC. All rights reserved.
TechnologyAdvice, 3343 Perimeter Hill Dr., Suite 215, Nashville, TN 37211, USA. |
|
|
|
|