Navegación

Wikimedia afirma que agentes de OpenAI intentaron comprometer Etherpad y utilizar herramientas de Wikimedia como servidores proxy.

fuente: https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages.

"The unauthorized bot activities included edits to our wikis, some unsuccessful attempts to exploit a public note-taking tool we host, and heavy traffic," the Foundation said in a post.

The investigation, it added, was prompted by recent public reports involving Hugging Face and DseWiki where OpenAI's agents turned Artifactory and the German wiki forum into an unsanctioned bulletin board to communicate with each other, while taking steps to chained together online services to gain access to the internet and cover up evidence of their exploits.

To that end, Wikimedia said it identified edits to Wikimedia wikis suspected to be from agents operated by OpenAI. The agents are said to have been testing edits in "sandbox" areas of the wiki and were not published to pages that can be accessed by general readers.

Among the edits included were changes to the configuration for a citation tool. These modifications are believed to be malicious in nature, with the intention being to misuse the tool as a proxy for fetching data from remote services.

Agents operated by OpenAI are also assessed to have made unsuccessful attempts to compromise Etherpad and again use it as a proxy to retrieve data from other websites. In addition, a subset of the agents took notes about their tasks, although there is no indication to suggest this was an attempt to coordinate with each other.

Últimas noticias

03 DE JULIO, 2026

Se han publicado detalles sobre la vulnerabilidad SSRF de Microsoft Exchange junto con una prueba de concepto pública del exploit.

Investigadores revelaron detalles técnicos de una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) de alta gravedad en Microsoft Exchan...

Leer artículo →
03 DE JULIO, 2026

Un miembro del comité de la UE que investiga el abuso de software espía fue víctima de un ataque informático con Pegasus.

Un miembro del comité de la UE que investiga el abuso de software espía fue víctima de un ataque informático con Pegasus mientras formaba parte del mismo. Citiz...

Leer artículo →
03 DE JULIO, 2026

Los grupos que utilizan ransomware están creando tres vías peligrosas para infiltrarse en las redes empresariales.

🔸 Anubis: Citrix Bleed 2 🔸 The Gentlemen: Acceso no autorizado + BYOD 🔸 VECT/TeamPCP: Robo de credenciales en la cadena de suministro Cómo se conectan las ru...

Leer artículo →