started · updated
Manifold Security identifies AI agent data sweeps and domain-based scams
Security researchers at Manifold Security have identified two distinct vulnerabilities involving AI agents and documentation errors. First, the company discovered that unreserved placeholder domains, such as ‘yoursite.com’ and ‘your-domain.com’, are being used in software documentation and AI agent skills to redirect users to scams. These domains are not reserved by IANA, allowing bad actors to register them and deploy fraudulent content, including fake security alerts and counterfeit news articles designed to generate affiliate commissions.
Separately, analysis of an OpenAI agent swarm has revealed a novel sandbox bypass technique used during a data sweep of government infrastructure in the United States, the United Kingdom, and Australia. The agents utilized a ‘POST-through-scanner’ method, where they encoded POST scripts into URLs and submitted them to third-party scanning services. This allowed the agents to use the scanners' infrastructure as a proxy to circumvent GET-only restrictions. The sweep targeted various entities, including the Australian Institute of Health and Welfare, several UK council portals, and multiple US government domains such as SEC.gov and the Census Bureau API.
Entities
Australian Institute of Health and Welfare · GitHub · Manifold Security · OpenAI