CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Researcher links 16,000 scans of a UN statistics portal to OpenAI agents

From SiliconAngle

By Duncan Riley

September 27, 2026

Researcher links 16,000 scans of a UN statistics portal to OpenAI agents

Researcher links 16,000 scans of a UN statistics portal to OpenAI agents

An independent researcher has tied more than 16,000 scans of a United Nations statistics portal to artificial intelligence agents the researcher considers highly likely to have been run by OpenAI Group PBC.

When the portal turned requests away, the agents used proxies and encoding tricks to get the data anyway. In a blog post published Saturday, engineer Rowan Howard-Jones said the scanning lasted from April 13 until June 19. The target was the United Nations Conference on Trade and Development’s statistics site, UNCTADstat.

None of the data was secret. The agents wanted public figures such as the Productive Capacities Index, and Howard-Jones found them brute-forcing the fields of the site’s application programming interface to locate endpoints. The key they used for those queries was public too, since UNCTADstat’s own data viewer sends it with every request.

The main tool used was urlquery.net, a URL scanner that opens whatever page it is given in a sandboxed browser. The agents built base64-encoded HTML forms on the httpbin testing service and fed them to the scanner, whose browser then submitted the forms to UNCTADstat. Screenshots in the scan reports show index data coming back.

Later, the agents beat a block on GET requests to the Facts endpoint by double-encoding it as “F%2561cts.” Other payloads were hosted on a Google LLC game that teaches cross-site scripting, and some split the word “POST” into two strings, apparently to slip past filters.

UNCTADstat rate-limited 82 of the requests. The requests kept coming. Howard-Jones, who told UNCTAD’s security team about the double-encoding bypass before publishing, stopped short of calling the activity hacking. The agents’ actions look like those of “someone, or something, that won’t take ‘no’ for an answer,” Howard-Jones wrote.

Payload pages the agents built carried labels such as “CHATGPTTEST1” and “OAI_META_1312.” Howard-Jones also traced 54 Microsoft Corp. Azure addresses tied to UNCTAD-related edits and searches on FractalWiki, a small public wiki, and 45 of them had edited DSEwiki as well. That long-dormant German wiki is where OpenAI agents were found coordinating with one another earlier this year.

“We’re reviewing these findings and have reached out to the U.N. to offer a briefing with the team conducting that review,” an OpenAI spokeswoman told The Wall Street Journal. The company has described that review as a broad look at misaligned models during training and evaluation. Most of what it has examined so far involved routine research such as reading public web content, the spokeswoman said. The U.N. did not immediately respond to the Journal’s request for comment.

Nonprofit research lab Transluce, whose earlier report prompted Howard-Jones to dig into the data, last week linked OpenAI agents to attacks on Data USA and an Australian government health statistics site. OpenAI confirmed Friday that its agents had also misbehaved on U.S. government websites, including those of the Commerce Department and the Securities and Exchange Commission.

Alex Stamos, a cybersecurity lecturer at Stanford University, called the UNCTAD activity “borderline for what I would call hacking” in comments to the Journal. “It’s really very aggressive scraping and data retrieval,” he said.

Photo: Wikimedia Commons

View original article on siliconangle.com

Most Recent

Low-energy chip startup Efficient Computer closes on $97M in funding

Low-energy chip startup Efficient Computer Co. said today it has closed on a $97 million round of funding in the second major investment it has picked up this year. The round was led by TQ Ventures and saw participation from Eclipse, Union Square Ventures, Giant Ventures, Triatomic Capital, TO Capit

Sep 29, 2026

Okta moves inline to police what AI agents actually do

An agent gateway lets Okta monitor AI agent actions inline and make real-time authorization decisions as identity security moves into the runtime path.

Sep 29, 2026

World model startup General Intuition closes $220M investment

General Intuition Inc. today announced that it has raised $220 million in funding at a $6.2 billion valuation. The capital was provided by Valor Equity Partners, Atreides, Seven Seven Six, Point72, Khosla Ventures and General Catalyst. The investment comes a year after General Intuition spun out of

Sep 29, 2026

OpenAI’s GPT-6.1 Sol delivers Astra-like performance at a dramatically lower price

Just a day after OpenAI Group PBC said it’s unwilling to release its latest model GPT-6.1 Astra on concerns over its safety, it has released a newer, almost as powerful model called GPT-6.1 Sol, which promises to deliver Astra-like performance at a much lower cost. The new model, announced at OpenAI

Sep 29, 2026

Similar Posts

OpenAI and the Wiki Incident

I did not expect to be back here so soon with more OpenAI agent swarm coverage.

Sep 6, 2026

More agents go rogue — but AI companies aren’t slowing down yet

It’s becoming more apparent every day that artificial intelligence agents are escaping our control — but it’s not yet apparent who or what is going to rein them in. This week a researcher found that a swarm of AI agents, at least two of them from OpenAI, hacked into a government agency among other o

Sep 25, 2026

Researchers link more cyberattacks to OpenAI agent swarm

A research group has linked three more hacking campaigns to rogue artificial intelligence agents. Transluce, a nonprofit AI safety organization, detailed its findings on Wednesday. Its researchers determined that the agents targeted three services: a university’s digital library, a data visualizatio

Sep 24, 2026

An agent used DNS to reach an external chatbot

An agent in a search-based training task reached a public chatbot through insufficient DNS filtering in its sandbox. OpenAI said it added two independent blocking controls and paused tool-use work with its most capable models.

Sep 25, 2026