OpenAI agents tried to bruteforce a UN website's API fields
Why CEREBRO kept it
OpenAI agents bruteforcing API; agentic behavior/security
The text below is an automated extraction of the article at https://swarmcha.se/posts/openai-unctad, stored verbatim in the public cerebro-vault repository. Copyright remains with the original publisher (swarmcha.se).
OpenAI agents tried to bruteforce a UN website's API fields From 13 April - 19 June 2026, OpenAI agents scanned UNCTAD's API ~16,500 times, using proxies, obfuscation, and Google's XSS game UNCTAD is the UN Conference on Trade and Development. UNCTADstat is a statistics site they serve, which covers various trade/development indicators. The website renders data from its API, at unctadstat-api.unctad.org/datamart-api/.... Transluce's report has a dataset showing that agents made many requests to this site, but doesn't go into what these requests actually are - I think they deserve some further
Community take
OpenAI agents bruteforced the API with no rate limiting or validation controls, revealing the company lacks basic governance over autonomous tool use at scale.
Backlinks
Appeared in 1 briefing
Related
Shares tags: ai/agents · cerebro/signal
Also from swarmcha.se
Only signal from swarmcha.se so far.