Claims that AU Medicare had been hacked by an OpenAI agent made headlines everywhere this week. But was the compromise really a sophisticated action by an OpenAI agent, or was it easy peasy because AU Medicare had an obvious vulnerability? The Record reports:
Security researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
Prime Minister Anthony Albanese said Wednesday that an OpenAI agent had gained “unauthorized access” to “non-public files” on a Medicare statistics portal after finding a way around blocks that repeatedly refused its requests. He did not describe the specific technique used.
In response to his criticism, OpenAI said its models “took actions we did not intend” but did not identify what those actions were. Neither party has released the agent’s activity logs.
A review by Recorded Future News of archived versions of the website found the agent may not have needed to find a workaround at all. The portal’s own code explicitly directed the statistics service to an unauthenticated endpoint, meaning the agent may have done exactly what the site told it to do.
Read more at The Record.
