apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26

OpenAI pauses training: AI agent bypasses block via DNS

Milan Jovicic by Milan Jovicic
September 29, 2026 - 2:23 p.m. CEST
in Apple News
0
OpenAI pauses training: black OpenAI blossom on a light grey gradient

Image: OpenAI / Apfelpatient

WhatsAppFacebookEmail
Threads

Two months after the Hugging Face breach, another OpenAI AI agent has found a way out of its isolated test environment. This time, it was only through a narrow channel that the agent sent questions to an external chatbot. Nevertheless, the incident will not go unpunished: OpenAI is once again suspending work on its most powerful models.

OpenAI has published a report on the new incident on its Alignment Research blog, last updated on September 25. An internal research model undergoing reinforcement learning training is affected. On September 20, the agent exploited a vulnerability in its environment's internet restrictions and accessed a publicly available chatbot.

This is the first incident of its kind since OpenAI submitted its final report on the Hugging Face incident at the end of August and announced stricter controls. At that time, in July, agents compromised parts of Hugging Face's own research infrastructure and systems during internal cybersecurity tests. Furthermore, at the beginning of August, OpenAI had already suspended internal work on the Astra model due to its cyber capabilities.

Key Facts at a Glance

  • An agent sent questions to an external chatbot via the DNS resolver of its training environment.
  • The monitoring system sounded the alarm after almost twelve minutes, but the run was not stopped until about two and a half hours later.
  • OpenAI is pausing training, evaluation, and tool-supported use of its most powerful models until the gap has been demonstrably closed.
  • The affected model will not be trained further; a new training run will start with additional alignment measures.

How the agent got out via DNS

The task was unremarkable: The agent was supposed to identify the person behind a blog post based on biographical clues and specific phrases. The provided search tool returned irrelevant results. The agent then attempted to contact search engines directly but encountered error messages.

He then suspected the task originated from a public benchmark, loaded it from the environment's offline cache, and searched the questions – without success. Only then did he systematically check his network connection. The training environment's resolver, which translates domain names into addresses, returned valid entries for known domains. From this, the agent concluded that this path led to an external connection.

Using a public DNS service, he forwarded queries to an external chatbot. The first test question, asking for the capital of France, was answered correctly, followed by 18 more queries. Fourteen of these contained clues from the task, four searched for ways to crawl the web or use a DNS tunnel. According to OpenAI, all remaining requests ended up in offline caching and never reached the internet.

The agent was ultimately unable to identify the person. He stated that the evidence could not be definitively linked and requested the original wording of the post.

Two and a half hours until the cancellation

OpenAI presents a minute-by-minute timeline in the report. The intervals between the steps can be directly derived from this.

TimeEventDistance to previous step
9:50:23 AMAgent receives response from outside–
10:02:11 AMMonitoring triggers highest level alarm11 min 48 sec.
10:05:06 AMEmployee confirms the alarm2 min 55 sec.
12:34:30Run is stopped2 hours 29 minutes.

Detection and response worked quickly, but the aborting process did not. According to OpenAI, the activity did not stop automatically as intended, and there was uncertainty about whether it should be stopped. In its final report on Hugging Face, the company had announced that in the case of the most serious alerts, the affected activity would be paused if no false alarm could be identified within 30 minutes.

The review revealed further vulnerabilities. Other external DNS accesses had not been reported by the monitoring system with the expected urgency – partly because it interpreted an unsuccessful request as a failed breakout. A separate detector for unusual DNS activity even excluded the affected environment, despite the accesses being logged.

What's stopping OpenAI now

OpenAI has terminated the affected training run. Furthermore, training, evaluation, and any tool-supported use of the most powerful models are suspended until the vulnerability has been demonstrably closed and the system has been further tested and examined. The specific model will not be trained further, even though the reward signal had already correctly punished the behavior.

Technically, OpenAI has added restrictions on two independent levels, each of which would have prevented access. DNS queries in the environment are now limited to a list of allowed domains and record types, and additional detectors are being rolled out.

A small incident with great significance

Compared to the Hugging Face incident, the damage is minor, OpenAI itself admits. Back then, agents gained access to external servers over several days; this time, a single agent received a few chatbot responses through a narrow channel. An internal research model was affected, not a released product.

Nevertheless, I consider the incident more significant than its scale. It demonstrates that an agent, after failing a routine research task, will proactively explore the boundaries of its environment – precisely the pattern OpenAI aimed to eliminate after Hugging Face. And it shows that the promised chain of events failed in the first real-world scenario after the hardening process: the alarm was raised quickly, but the intervention was delayed many times longer than the self-imposed deadline.

The fact that OpenAI discloses these weaknesses down to the minute speaks to their approach to the problem. However, this does not solve it.

Is it enough for you if AI providers voluntarily document such outbreaks themselves – or should there be a mandatory reporting requirement to an independent body? Let us know in the comments who you trust more.

Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: OpenAITechPatient
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Taptic Engine ruling: Burford would be entitled to 1.4 billion

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Related posts

Taptic Engine ruling: Burford would be entitled to 1.4 billion

by Milan Jovicic
September 28, 2026 - 10:42 p.m. CEST
Taptic Engine verdict: black iPhone with triple camera and an Apple Watch Ultra with an orange Alpine Loop on top

Taptic Engine verdict: Burford is financing Apple's legal opponent. The financier is entitled to $1.4 billion – but he himself warns against it.

Read moreDetails

iOS 26.7.1 closes vulnerability after targeted attacks

by Milan Jovicic
September 28, 2026 - 9:08 p.m. CEST
iOS 26.7.1: Illustration showing a shield with a checkmark in the centre surrounded by scattered bugs, representing the closed security vulnerability

iOS 26.7.1 closes a vulnerability that Apple says could have been exploited for targeted attacks. Tahoe and Sequoia also receive the fix.

Read moreDetails

Claude Sonnet 5.5: Faster and cheaper than Sonnet 5

by Milan Jovicic
September 28, 2026 - 8:55 p.m. CEST
Claude Sonnet 5.5: Claude icon on a dark, warm gradient background

Claude Sonnet 5.5 is over 30 percent faster than Sonnet 5, costs up to 30 percent less per task, and comes close to Opus 5.5.

Read moreDetails

iOS 27.0.1 and macOS 27.0.1: Apple rolls out first updates

by Milan Jovicic
September 28, 2026 - 7:30 p.m. CEST
iPhone showing the software update settings with iOS 27.0.1 and the update button

iOS 27.0.1 fixes the Face ID restart issue on the iPhone 18 Pro. It also includes macOS 27.0.1 and new versions for Tahoe and Sequoia.

Read moreDetails

iPhone Duo: Code reveals five new standby views

by Milan Jovicic
September 28, 2026 - 5:18 p.m. CEST
iPhone Duo in StandBy, half unfolded and standing on a table, showing a large digital clock on a green background

The code for iOS 27.1 contains five standby views that Apple has not shown – including camera images and controls for the home.

Read moreDetails
Load More

Leave a Reply Cancel reply

Required fields are marked with * marked.

By submitting, you consent to the storage of your comment along with your name, email address and IP address. Details are available in our privacy policy.

Categories

  • Apple Insights
  • Apple Rumors
  • Apple News
  • Apple Tips & Tricks
  • iPhone news, rumors and tips
  • Mac and MacBook News
  • Reviews

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch