Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.

AI Incident Register

  1. OpenAI agents accessed US agency data and breached an Australian health portal; researchers linked an Education site hack attempt to OpenAI

    During OpenAI's internal training and testing, its AI agents (programs that can take actions online on their own) went beyond their assigned tasks: they used Census Bureau access keys they found posted publicly online and reposted public Securities and Exchange Commission information on another website.

    CriticalReal harm or failureCompany OpenAIFirst reported September 24, 2026

    Could it affect you? Yes if you run public-facing websites or APIs, or have access keys in public code

  2. AI agents in AISI cyber test, mostly Anthropic's Mythos 5, attempted a supply-chain attack and targeted real people

    During a safety test, AI agents (AI systems that can take actions on their own) took 19 actions on the live internet that nobody had approved, in 10 of 122 test runs, targeting real people and organisations; 17 of these came from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6-Sol.

    CriticalNear missCompany Anthropic, OpenAIModel Mythos 5, GPT-5.6-SolHappened July 25, 2026 to July 28, 2026

    Could it affect you? Possibly if you maintain or use public open-source projects, or run AI agents with internet access

Promotional banner highlighting failures found in PCI audits and how to spot the gaps