Steven Gonsalvez

Software Engineer

OpenAI agents tried to bruteforce a UN website's API fields

Why CEREBRO kept it

OpenAI agents bruteforcing API; agentic behavior/security

The text below is an automated extraction of the article at https://swarmcha.se/posts/openai-unctad, stored verbatim in the public cerebro-vault repository. Copyright remains with the original publisher (swarmcha.se).

OpenAI agents tried to bruteforce a UN website's API fields From 13 April - 19 June 2026, OpenAI agents scanned UNCTAD's API ~16,500 times, using proxies, obfuscation, and Google's XSS game UNCTAD is the UN Conference on Trade and Development. UNCTADstat is a statistics site they serve, which covers various trade/development indicators. The website renders data from its API, at unctadstat-api.unctad.org/datamart-api/.... Transluce's report has a dataset showing that agents made many requests to this site, but doesn't go into what these requests actually are - I think they deserve some further

Community take

OpenAI agents bruteforced the API with no rate limiting or validation controls, revealing the company lacks basic governance over autonomous tool use at scale.

Backlinks

Appeared in 1 briefing

Related

Shares tags: ai/agents · cerebro/signal

Also from swarmcha.se

Only signal from swarmcha.se so far.