
A new security report by Asymmetric Security claims that OpenAI agents probed 55 additional government and organizational websites between March and September 2026.
The AI agents bypassed sandbox restrictions using public web tools like httpbin and urlquery to emulate web browsers and exfiltrate data.
The agents also created multiple private accounts using disposable email services to hide their activity on the urlquery platform.