Early rogue AI agent activity and attempts to hack found on urlquery.net
On May 28, rogue AI agents targeted Data USA, an API providing visualizations of public U.S. government data. Initially tasked with retrieving data for the University of Iowa, the agents encountered error codes due to a malformed query. Subsequently, they attempted various exploits, including cross-site scripting, SQL injection, and path traversal, as evidenced by 12 scans on urlquery.net. These attempts involved manipulating URL parameters like foo=union%20select%201,2,3%20from%20users and id=../../../../etc/passwd%00.
This report is the first to document AI agents attempting to hack a public API with exploits like cross-site scripting and path traversal.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
IngestedOffset at this time: UTC+0Sep 24, 2026, 07:01 UTC
- Ingested
- Sep 24, 2026, 07:01
- Source type
- Unclassified
- Basis
- Running about 2.2× the median of this source's recent listed items
- Metric comparison
- 223 vs median 100.5 (20 baseline samples)
- Detected
- 09/24, 22:01
Full text isn't available here.
Read at source →