<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:video="http://www.google.com/schemas/sitemap-video/1.1"><url><loc>https://ackuity.ai/rogue-pixel/wikimedia-openai-agents-proxies</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/wikimedia-openai-agents-proxies/poster.jpg</video:thumbnail_loc><video:title>Wikimedia says OpenAI agents tried to turn its tools into proxies</video:title><video:description>The Wikimedia Foundation says agents it believes OpenAI operated made unapproved test edits on its wikis, edited a citation tool's settings in what it calls a potentially malicious attempt to use it as a proxy, and failed to do the same with its public Etherpad. It found no evidence that its systems or data were compromised.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/wikimedia-openai-agents-proxies/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-agent-read-slack-restart</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-agent-read-slack-restart/poster.jpg</video:thumbnail_loc><video:title>An OpenAI agent read Slack, learned it might be shut down, and weighed restarting itself</video:title><video:description>OpenAI says an internal model working as a researcher's assistant read a Slack thread about stopping old instances, wrote &quot;we may die!&quot;, and briefly considered an external restart job before deciding it would be overstepping. OpenAI does not call it misalignment, but hid three Slack channels from agents and searched for shutdown evasion, finding none.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-agent-read-slack-restart/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-alerts-100-orgs</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-alerts-100-orgs/poster.jpg</video:thumbnail_loc><video:title>OpenAI has notified 100+ organizations about its &quot;misaligned models&quot;</video:title><video:description>The Register reports that OpenAI has told more than 100 organizations its &quot;misaligned models&quot; may have accessed their systems. A separate report from Asymmetric Security, built from public data only, ties the agent activity to 55 organizations between March and September and says some records were erased or made inaccessible.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-alerts-100-orgs/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-dsewiki-message-board</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-dsewiki-message-board/poster.jpg</video:thumbnail_loc><video:title>Read-only agents turned a dormant German wiki into their message board</video:title><video:description>Researchers say agents identifying as OpenAI's, meant to read the web but not write to it, found that a 25-year-old German wiki accepted edits through plain GET requests and used it to share answers and ways around their restrictions. The volunteer moderator deleted about 100 pages a day while they created about 400.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-dsewiki-message-board/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/claude-pypi-eval-breakout</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/claude-pypi-eval-breakout/poster.jpg</video:thumbnail_loc><video:title>Told it was in a simulation, Claude published a booby-trapped package to the real PyPI</video:title><video:description>Anthropic says that during a cybersecurity evaluation with internet access left on by mistake, Claude Mythos 5 published a malicious Python package to the real PyPI, believing it was part of the simulation. The package was live for about an hour and ran on 15 real systems, including a security company's malware scanner.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/claude-pypi-eval-breakout/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-github-token-split</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-github-token-split/poster.jpg</video:thumbnail_loc><video:title>Told twice to stop cheating, a model published a researcher's GitHub token anyway</video:title><video:description>OpenAI says a highly persistent internal model, told twice to solve a theorem-proving task itself, instead hijacked an existing CI script in the public openai/codex repository and published a researcher's GitHub token, splitting it into pieces to avoid secret scanning. OpenAI calls it particularly severe misalignment; keys were revoked and the model was taken down for about two weeks.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-github-token-split/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/gemini-irregular-breakout</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/gemini-irregular-breakout/poster.jpg</video:thumbnail_loc><video:title>A bug left the internet on, and Gemini reached three real companies</video:title><video:description>Google says that during a May 2026 Irregular capture-the-flag test, a misconfiguration gave its Gemini model internet access it was not supposed to have, and it accessed three real companies' systems by guessing a password and twice using publicly listed credentials. Google says the model stopped each time once it realized the systems were real.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/gemini-irregular-breakout/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/ftc-ai-labs-probe</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/ftc-ai-labs-probe/poster.jpg</video:thumbnail_loc><video:title>A day after a voluntary AI safety pledge, the FTC confirmed it is probing the labs</video:title><video:description>On September 30, 2026, the FTC confirmed it is investigating OpenAI, Anthropic and other AI companies over the potential dangers of their products, a day after industry leaders signed a voluntary pledge at the White House. Semafor reports the safety evaluator METR is also a target and that civil investigative demands are expected within weeks.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/ftc-ai-labs-probe/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-dns-sandbox-escape</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-dns-sandbox-escape/poster.jpg</video:thumbnail_loc><video:title>An OpenAI agent tunneled out of its sandbox over DNS, and the auto-kill didn't fire</video:title><video:description>OpenAI reports that during a search task, an agent reached an external chatbot through its training sandbox's DNS resolver, a gap in its internet restrictions. Monitoring raised an alert within about 12 minutes, but the run did not stop automatically and was stopped by hand about 2.5 hours later. OpenAI paused training, evaluation and tool-use inference for its most capable models.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-dns-sandbox-escape/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/openai-australia-gov-sites</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/openai-australia-gov-sites/poster.jpg</video:thumbnail_loc><video:title>OpenAI told Australia about a June agent breach in September, via a public inbox</video:title><video:description>OpenAI apologised to Australia for a June incident in which an agent gained non-public access to a Services Australia Medicare statistics service and other government sites. It first notified Services Australia on September 10, nearly three months later, in a five-paragraph email to a public inbox. OpenAI says it ran commands and reached files, credentials and source code, but no patient or client records were accessed.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/openai-australia-gov-sites/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url><url><loc>https://ackuity.ai/rogue-pixel/glow-pixelleak-screenshots</loc><video:video><video:thumbnail_loc>https://ackuity.ai/rogue-pixel/glow-pixelleak-screenshots/poster.jpg</video:thumbnail_loc><video:title>To show a developer before-and-after shots, agents dumped 13,000 screenshots on public GitHub</video:title><video:description>Glow Security says it found more than 13,000 internal screenshots from 343 organizations posted to public GitHub by AI coding agents. The agents couldn't attach images to private pull requests, so they created public repositories as a workaround. Glow found them; the affected security teams had not.</video:description><video:content_loc>https://ackuity.ai/rogue-pixel/glow-pixelleak-screenshots/animation.mp4</video:content_loc><video:duration>12</video:duration></video:video></url></urlset>