01 / AGENT SAFETY / COMPANY INCIDENT REPORT
A DNS gap bypassed an agent’s internet restrictions
Conceptual sequence from OpenAI’s incident account. Detection, stopping a run, and validating stronger controls are separate steps; spacing does not represent elapsed time.In a September 25 report, OpenAI says a research agent reached an external chatbot through insufficient DNS filtering. It added two blocking layers; training, evaluation and tool-using inference for its most capable models remain paused pending validation and further testing.
Read the source ↗ alignment.openai.com02 / SECURITY / COMPANY INVESTIGATION
EvilTokens turned stolen inbox access into fraud planning
Microsoft’s September 22 report says partners disrupted EvilTokens, which used AI to analyze compromised inboxes and identify impersonation targets. The takedown does not secure every affected account: stolen sessions and tokens can remain usable after a password reset.
Read the source ↗ blogs.microsoft.com