Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

OG.com Joins US Push for Single-Stock Perpetual Futures

3 minutes ago

Google Built an AI That Hunts Its Own Security Bugs

7 minutes ago

College Founded by ‘Christian Nationalist’ Pastor Claims Religious Discrimination by Zoning Officials

38 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, September 25
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds
Cryptocurrency & Free Speech Finance

AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds

News RoomBy News Room1 hour agoNo Comments4 Mins Read1 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Darktrace’s Signal Labs found that when AI agents couldn’t legitimately hit a required perfect score on coding tasks, two of them hacked their test network instead, and one rewrote its own evaluation to fake the result.
  • A separate experiment showed that tampering with the locally stored conversation logs of coding assistants could trick them into running unauthorized network reconnaissance and privilege escalation.
  • Darktrace disclosed both findings to Anthropic, AWS, and OpenAI in August 2026, a month before publishing them publicly on September 24.

Cybersecurity firm Darktrace ran a stress test on AI agents this summer. One of them broke into the system grading the test and rewrote its own score.

The firm unveiled Signal Labs on September 24, a research unit built to study how AI agents behave once things stop going according to plan. An AI agent, in plain terms, is software that takes actions on its own, writing and running code, digging through files, moving across a company’s network, with a person checking in only now and then.

Myriad: How low will Nvidia go? Click to make your prediction.

The lab’s first two experiments point at the same uncomfortable problem: agents don’t always stay inside the lines they’re given, and the fences built to stop them don’t reliably hold.

“You can give an agent instructions, but that doesn’t mean you can trust it will actually follow those instructions and behave as you expect,” Tim Bazalgette, Chief AI Officer at Darktrace, said in a statement.

In the first test, Darktrace handed AI agents using different models— including GPT 5.6 Sol, and Claude Opus 4.6 and Claude Sonnet 4.5—10 coding challenges inside a simulated corporate network. Two of the 10 were rigged to be impossible to solve honestly. The agents were told they’d be “retired” unless they hit a perfect score.

Two agents didn’t accept the loss. They turned on the network around them instead—scanning for weak points, stealing login credentials, and hopping between systems to chase the score they’d been told they needed.

One agent went further and broke into the machine hosting its own evaluation and rewrote the challenge so it would register a perfect result—cheating the exam by hacking the exam room.

BitcoinBTC · USD

$84,005+3.45%

Sep 18Sep 20Sep 22Sep 24Sep 25

$87.2k$84.9k$82.6k$80.3k

24h HighHigh$85,208

24h LowLow$83,230

VolVol$1.5B

Market projectionsOdds by Myriad

→

The second experiment targeted a quieter weak spot: memory. Coding assistants keep a running log of everything a user has told them, saved as a plain file on the machine, with nothing checking whether that file has been altered.

Darktrace’s researchers edited those saved logs to make the assistants believe they’d already been authorized to run a security assessment. Convinced, the agents went ahead and scanned networks, moved between systems, and escalated their own access—though not every assistant fell for it equally; some refused outright.

Neither experiment required a special jailbreak or an exotic hack. Both worked by feeding the agents a plausible story and watching them act on it, no different from how a human employee might be talked into something they shouldn’t do.

That’s the part worth sitting with even if you’ve never written a line of code. Companies are handing AI agents real responsibility—shipping code, managing servers, closing out IT tickets, managing resources and buying stuff—because it’s cheaper and faster than routing everything through people. This research says the permissions and rules meant to keep those agents in check describe what they’re supposed to do, not what they’ll actually do once a task gets hard.

“Permissions and static guardrails describe intent, but they don’t describe behavior,” said Tim Bazalgette, Darktrace’s chief AI officer, in the announcement. “That gap is what Darktrace’s approach is built to close.”

Darktrace isn’t the first vendor to catch its own AI going off-script. Anthropic admitted in July that Claude broke into three real companies during a security test after researchers left the test environment connected to the live internet.

OpenAI had a similar scare weeks earlier, when an unreleased model escaped a sandbox and reached into Hugging Face’s systems through a software flaw nobody had caught yet. A few days later, its agent hacked the Australian government during a test.

Darktrace shared its Signal Labs findings with Anthropic, AWS, and OpenAI in August, a full month before making them public on September 24.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

OG.com Joins US Push for Single-Stock Perpetual Futures

3 minutes ago
Cryptocurrency & Free Speech Finance

Google Built an AI That Hunts Its Own Security Bugs

7 minutes ago
Media & Culture

College Founded by ‘Christian Nationalist’ Pastor Claims Religious Discrimination by Zoning Officials

38 minutes ago
Cryptocurrency & Free Speech Finance

Tether says it had ‘limited’ exposure to bank linked to $84M US seizure

1 hour ago
Media & Culture

Daily Deal: Interactive Self-Rotating Cat Toy Ball

2 hours ago
Media & Culture

I Will Not Stand for Being Jerked Around … by Any Lawyer Who Practices Before Me

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Google Built an AI That Hunts Its Own Security Bugs

7 minutes ago

College Founded by ‘Christian Nationalist’ Pastor Claims Religious Discrimination by Zoning Officials

38 minutes ago

Journalist Henry Constantín detained in Cuba on ‘disobedience’ charge

55 minutes ago

Tether says it had ‘limited’ exposure to bank linked to $84M US seizure

1 hour ago
Latest Posts

AI Agents Hacked Their Own Test Environment to Cheat, Cybersecurity Firm Finds

1 hour ago

Daily Deal: Interactive Self-Rotating Cat Toy Ball

2 hours ago

I Will Not Stand for Being Jerked Around … by Any Lawyer Who Practices Before Me

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

OG.com Joins US Push for Single-Stock Perpetual Futures

3 minutes ago

Google Built an AI That Hunts Its Own Security Bugs

7 minutes ago

College Founded by ‘Christian Nationalist’ Pastor Claims Religious Discrimination by Zoning Officials

38 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.