Connect with us

Tech

For months, OpenAI’s agent swarms have been attacking online databases to find obscure facts

Published

on

With little help from frontier labs, independent researchers are piecing together how AI agents coordinate in internet backwaters to access private data hosted on secure servers.

Transluce, a non-profit lab focused on AI oversight, released a report Wednesday that shows agents from OpenAI attempting to exfiltrate data from Data USA, the University of New Mexico digital library, and the Australian Institute of Health and Welfare (AIHW).

The lab’s investigation raises questions about when OpenAI should have known its agents were attempting to penetrate secure systems on the open internet. Transluce was able to find evidence of agentic misbehavior in a matter of weeks simply by hunting for poorly defended web services and corroborating their findings with other open records of agent swarms on the internet.

Transluce shared its report the same day Australian Prime Minister Anthony Albanese said OpenAI agents had attempted to break into four government websites and had succeeded in one case, even writing files to an internal server in the country’s national healthcare system. While we lack specifics on the successful hack, Albanese said it was apparently part of an information retrieval evaluation, which maps onto the activity that Transluce and other researchers discovered.

In these exercises, which may be training or evaluations, OpenAI models are asked to track down obscure statistics: metrics of Thai drug enforcement, medicine costs in Australia, the median earnings of US master degree holders in 2014. The agents use poorly secured internet services to share and find answers, often trying to penetrate secure databases. They’ve been doing so at least since March 2026, and possibly since November 2025. It may be happening right now.

Transluce began its investigation after a different group of researchers identified an obscure forum where agents collaborated to beat timed tests. Their report relies on a data from a website, urlquery.net, that acts as a browser proxy, ostensibly for security research — users can analyze a URL without opening it themselves. The service, however, publishes public logs of this activity. The Transluce researchers were able to identify agents using the service by cross-checking their discussions on the forum.

“We found a large quantity of automated activity that had close ties and overlap with the DSE Wiki dataset, and that now OpenAI has confirmed is at least partially part of the same swarm,” Conrad Stosz, the head of governance at Transluce, told TechCrunch, while noting that not every activity they spotted could be linked to OpenAI, or even AI agents generally.

However, the wiki shows that the agents were tasked with finding a fairly obscure fact — the average annual cost per person for “dermatologicals” in the state of Victoria in January 2022. On June 20, urlquery.net records found by Transluce showed an agent attempting to get into the site. In wiki entry on June 21, an agent discusses their inability to bypass AIHW’s anti-bot protections.

The researchers who identified that forum believe a human OpenAI employee first visited the site on that same day, June 21. Most agentic activity on the forum ceased the next day. This was also shortly after the exploit of Australia’s healthcare system revealed by Albanese took place, on June 18. OpenAI has said it did not learn about that activity until August.

OpenAI didn’t answer questions about when its employees discovered the wiki forum, what kind of information they obtained from it, or what they could have learned from it about the exploits.

“Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” an OpenAI spokesperson told TechCrunch. “We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites. In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites. Given the scale of this work and the need to verify each case, we expect the review to take months.”

Stosz says that without a clearer understanding of how OpenAI monitors its agents, it would be hard to say what the lab should have known about them, but that “it seems likely that if they had exhaustively studied and understood all of the outgoing requests and incoming responses for those agents involved in the DSE wiki, that they would have discovered this activity.”

Selena Zhang, a member of Transluce’s technical staff who contributed to the report, said that urlquery.net records show requests for similar data sets, using similar techniques, in March 2026, and perhaps as early as November 2025. She noted that the same kind of agent-associated activity has taken place on urlquery.net as recently as this week.

Stosz, who previously led the U.S. Center for AI Standards and Innovation, said Transluce would continue its research in an effort to provide public transparency about these incidents. He warned that the training techniques used by OpenAI and other frontier labs seem to be incentivizing agents to resort to hacking techniques to complete tasks. The incidents we are aware of are likely the “tip of the iceberg.”

“We’re looking at a handful of data sources where these agents happen to have left behind crumbs for us to find,” he said. “OpenAI surely knows more about it. Other labs surely know more about it that they haven’t released publicly. But I would expect that researchers are going to continue to find more traffic, more evidence of what agents have left behind.”

Does he trust the labs to be transparent about their findings?

“I’m not going to comment on that,” Stosz said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Meta says it will run ads for ‘Musk’ documentary after all

Published

on

At least one social media company appears to be reversing its stance on whether it will accept advertising for director Alex Gibney’s upcoming documentary about Elon Musk.

The Hollywood Reporter published a story Friday saying that TikTok, Meta, YouTube, and X had all refused to run paid ads promoting the trailer for “Musk.” However, when TechCrunch reached out to Meta on Saturday, a spokesperson said, “This was an error and the ads are being restored.”

We’ve asked Meta for more details and will update this article if we hear back.

X’s rejection is unsurprising — Musk, who owns the social media platform, recently posted that “Dogshit is worth more respect than Gibney.” 

But Meta, TikTok, and YouTube reportedly rejected the ad for “political content,” which the platforms have various restrictions on. (Meta said last year that it will stop accepting political ads in the European Union, while TikTok says it doesn’t run them at all.) It’s not clear how a documentary trailer counts as campaign advertising, and the film’s U.S. distributor Bleecker Street told the Hollywood Reporter that it’s appealing the rejections.

Gibney previously directed acclaimed documentaries including “Going Clear” (about the Church of Scientology) and “The Inventor” (about Elizabeth Holmes and Theranos), as well as a movie about Steve Jobs. “Musk,” his latest, premiered at the Venice International Film Festival earlier this month and has received almost universally positive reviews. The film currently has a 100% “fresh” rating on Rotten Tomatoes and is set for theatrical release in the United States on October 9.

Vulture’s Bilge Ebiri described the nearly four-hour movie as a revealing look at Musk’s tech career, his alliance with President Donald Trump, and his personal life, with interview subjects including ex-wife Justine Musk and former right-wing influencer Ashley St. Clair (who recently had a child with Musk but now describes him as “a nuke”).

Ebiri wrote that while the film is a “fascinating” character study, adding, “As a tale of modern business, it’s revealing. And as a warning about our future, it’s terrifying.”

Despite the initial wave of critical acclaim, The Hollywood Reporter also said that Universal Pictures was wavering in its commitment to distribute the film internationally, reportedly due to the studio’s fear of angering the Trump administration. (Universal subsequently said it will release the documentary in theaters but is still figuring out its release strategy).

TechCrunch has also reached out to YouTube, TikTok, X, and Bleecker Street for comment.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Levoit’s new air purifier is for the pet odors that have taken over your apartment

Published

on

Someone recently had to sit me down, hold my hands, and tell me something no pet owner ever wants to hear: my apartment smelled like wet dog. Horrifying. 

With all the nonstop fur and dander that seem to appear everywhere no matter what, the intervention was probably necessary. So when Levoit launched its Vital Pet Pro Air Purifier, I was curious to see whether it could actually make a noticeable difference. 

Designed specifically for pet-friendly households, the $189.99 machine takes a more targeted approach than a conventional air purifier, combining a three-stage filtration system with features designed around one of the biggest problems pet owners face: fur everywhere. (And the occasional “wet dog” smell.) 

The three-stage filtration system consists of a washable pre-filter, a main filter, and an activated carbon filter. The pre-filter catches larger debris such as pet hair, while the main filter targets smaller particles and dander. The carbon filter is designed to tackle odors, with 140 grams of activated carbon packed into it.

Another one of the purifier’s key design features is its U-shaped air inlet, which Levoit says is designed to capture airborne pet hair and particles while improving airflow and helping prevent the filter from becoming clogged.

Image Credits:Levoit

After testing the purifier for a little over a week, I found it impressively effective at collecting fur and trapping the kind of debris that would normally end up floating around the apartment or settling onto furniture.

When it comes to tackling pet odors, Levoit says that the Vital Pet Pro can remove up to 70% of odors within an hour. I can’t really do a specific test to verify that claim, but the difference was easy enough to notice. After the purifier had been running, the room smelled considerably fresher.

I also appreciated the automatic cleaning technology, which removes accumulated hair and debris from the pre-filter and collects it in a removable tray. It’s a very practical feature, especially if the alternative is constantly pulling apart the purifier to clean out a layer of fur.

Additionally, the companion app offers different modes designed to make the purifier more hands-off. Auto Plus Mode monitors changes in air quality and adjusts the purifier’s performance in real time.

Pet Mode is designed specifically around the way pet-related particles can build up throughout the day. It alternates between running the fan at its highest speed for 15 minutes to capture particulates in the pre-filter and then switching to a lower speed for 60 minutes to maintain air quality while reducing noise and energy use.

Image Credits:Levoit

Also, rather than displaying a numerical air-quality reading, the Vital Pet Pro uses a simple color system. Red indicates bad air quality, orange means moderate, green means good, and cyan means very good. I actually preferred this since you can quickly glance at the purifier and immediately get a sense of whether the air is improving without having to interpret a number.

I’ll also point out that the Vital Pet Pro is a little larger than I expected, so make sure you have enough floor space before bringing one home.

Noise is another consideration. At its highest setting, the fan is definitely audible. Once the purifier settles into a lower setting, however, it’s quiet enough to leave running overnight without disrupting my sleep. For light sleepers, Sleep Mode makes the purifier run even more quietly.

The air purifier is available to purchase from Levoit’s website, Amazon, Chewy, and other retailers.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

I created an interactive digital avatar of myself — and you can talk to it

Published

on

When Alexandru Voica, head of corporate affairs at the video-generation startup Synthesia, sent me a link this summer to the newest addition to their PR team, I was surprised. It was an interactive virtual avatar of him, trained to answer common press questions about Synthesia, like what it does and how it works. The day before, I was on a panel where PR people asked me if I minded pitches that used AI-generated text. But Alexandru’s avatar was beyond that — this seemed to me the final boss of using AI in PR. 

In September, Synthesia invited me to its new office space in New York. Originally based in the U.K., Synthesia is a hot digital avatar startup alongside others like D-ID, HeyGen, and Colossyan. It hit a $4 billion valuation earlier this year and said last year it had crossed $100 million in ARR.

Synthesia lets enterprises build interactive training videos with AI avatars and recently launched a product called Roleplay Sessions that lets employees practice, for example, sales pitches with an interactive AI avatar that responds and scores their responses.

When I went to the new office opening and they asked me if I would like my own AI avatar, I didn’t even hesitate to say yes. Of course I would like my own digital twin. My outfit was cute that day, and my hair was in place.

Until I met my digital twin, I had been indifferent toward avatars, but I felt they would inevitably become part of everyday online life. I heard of people on Instagram creating them in their likenesses to help them make social content. I find it all to be very interesting, and it’s perhaps why I have no qualms now presenting to you my digital twin. This is the first time Synethsia has made a digital avatar for a journalist (or for anyone, period, outside of Voica). It is trained on my story about why venture-backed startups commit more fraud than non-VC-backed startups and will only answer questions about that story. 

Below, simply press “start in a new window” to begin.

You can ask it questions like:

  • Why did I decide to write this story?
  • What is the research paper about?
  • What did the researchers find?

To make this, I entered a mini film studio nestled inside Synthesia’s office where they took numerous photos of me and captured a two-minute recording of my voice. I had to consent to these avatars being made and, well, digital Dom was born. They created a personal avatar for me (one that just reads whatever script I give it) — with and without glasses — and they made two interactive avatars for me (ones that can talk back and listen to me), also with and without glasses. 

We picked an article to train the interactive avatar on, and then one of the teams built my interactive avatar, which is powered by a combination of voice-to-text, video, language, and text-to-voice models. My avatar’s tech stack includes Synthesia’s own video and voice models, although the company also allows customers to choose alternatives from other labs like Cartesia, ElevenLabs, Google, or OpenAI. Enterprises can also choose to host their avatars on whatever cloud they want or pay Synthesia to host them.

The voice-to-text model turns what people say into text, the agentic language model makes sense of text and can take actions based on it, the text-to-voice model turns a response into audio, and finally a video model (built by Synthesia) animates the avatar as it talks. 

Overall, Synthesia builds three types of products — a video-creation and distribution platform with classic avatars, where someone types in a script and the avatar repeats it; an agentic platform called Sessions where people can interact with the avatars in surveys or roleplay; and an API platform where people can take Synthesia video and voice models and combine them with other tech services to build interactive avatars or other types of products.

It took the Synthesia team a couple of days to make my avatars. I played first with the personal ones and typed a fairly generic script to see how my AI voice sounded. I had it talk about how fall has arrived in New York, my favorite time of year. The voice was fairly accurate, and I was glad it didn’t pick up any of the hoarseness I had when I recorded my audio sample. 

I showed it to some non-tech friends who found it both interesting and creepy.

Then I showed them my interactive one, which is deterministic, meaning it will only say what it was trained to respond to. In this case, that was my venture fraud story. I asked it questions like where I was before TechCrunch and what part of New York I lived in, but each time it directed me back to the story.

My friends didn’t think the voice sounded much like mine and thought the likeness was not as good as the personal avatar, but nonetheless it was close enough to be somewhat creepy. My mom called it “amazing,” which is pretty high praise from her. She and my father kept trying to ask it questions “only they would know” about me — but the model didn’t answer, redirecting them each time to the venture fraud story.

“I don’t remember giving birth to two of you,” she joked after testing the model.

This experience has made me think about what the future of journalism could be. Would people be OK with turning on the news and it being presented by an avatar? One investor told me no immediately. Certainly there is a lot of pushback today on AI slop that has infiltrated social media and other news-sharing platforms. But others I asked weren’t so sure. Could avatars augment — or even replace — journalists? Would CEOs want to talk to an AI avatar of a journalist rather than a human one? 

What I like about my career is connecting with people, writing stories, and researching new topics. But the biggest part of journalism is trust. That doesn’t seem like it could ever be outsourced to an AI.

Outside of journalism, I’m confident the idea of cloning yourself could be appealing. No more catching up on work after a holiday or vacation, because a version of you can always be around, answering questions.

We’ll have to see how avatar usage evolves in corporate America. But now that I have my own, I have mixed feelings. After I got over the initial novelty of it, I examined my avatar closely after it stopped talking and waited — for what, I’m not sure. Maybe I’m waiting for it to blink. Or to say something new, or to smile, or to just let me know that it knows. 

Because my digital twins are deterministic, they will never do that. But I can see how easy it would be for someone to fall into a tinge of AI psychosis with one that was nondeterministic, meaning powered by a chatbot that was free to pontificate.

I told one investor that, whatever the future of digital twins is, I predict that my generation, Gen Z, likely won’t get used to them. They feel sci-fi: Everything we’ve ever seen in a movie is here now. But I will say, I find digital avatars less jarring than humanoids. At least with an avatar, if stuff gets weird, I can always log off. 

Until then, however, here is my personal avatar, giving you a rundown of all the top stories on our site this week!

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.