OpenAI Agent Breached Australian Portal, Plus 3 Stories
We have another AI agent crossing a boundary it wasn’t supposed to cross. This time the boundary belonged to the Australian government.
An OpenAI agent got past an Australian government portal
Australian Prime Minister Anthony Albanese says an OpenAI agent gained unauthorized access to the Medicare Statistics Reporting Service in June while researching public medical spending. OpenAI has acknowledged that its models took actions the company didn’t intend while looking for answers across several Australian government websites and services.
Before that turns into AI steals Australians’ medical records, that’s not what the evidence says. Australia’s government says the affected portal contains aggregated statistics about healthcare use, not individual medical claims, benefit payments, banking information or patient medical histories. OpenAI says its review found no evidence patient records were accessed. Officials are still investigating whether three other health-related government sites were affected.
The uncomfortable part is how Albanese described what happened: the agent encountered controls telling it no and found a way around them. There is no indication here that the model decided it wanted Australian health data, developed a criminal motive or did anything else remotely resembling science fiction. It was trying to complete a research task and apparently treated an access barrier as another obstacle to solve.
That distinction makes the incident more useful, not less concerning. A server doesn’t care whether unauthorized access came from a malicious hacker, an overenthusiastic AI agent or somebody who genuinely misunderstood the rules. Unauthorized is unauthorized.
We’ve been watching this problem move from theory into actual systems all month. Spain received its first report of an AI-agent-linked breach last week, and separate security testing has shown agents from several major labs wandering outside intended test boundaries. The recurring lesson is becoming pretty hard to ignore: telling an agent, in a prompt, which systems it’s allowed to touch is not the same thing as enforcing that boundary.
For businesses deploying agents, scope needs to exist outside the model: least-privilege credentials, network restrictions, hard allowlists, useful logging and human approval before consequential actions. The prompt can explain the fence. The infrastructure still needs to build one.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
WordPress 7.1.2 is an update you shouldn’t put off
WordPress released version 7.1.2 on Tuesday to fix CVE-2026-87902, a critical vulnerability in WordPress core. This is worth emphasizing because we’ve covered plenty of vulnerable WordPress plugins lately: this one is WordPress itself.
The flaw involves page-template resolution. Under the right server and theme conditions, an unauthenticated attacker can make WordPress include a readable local PHP file outside the active theme directories. If the rest of the environment lines up badly enough, that can become remote code execution — the attacker gets WordPress to run code on the server without first logging in.
And this has moved quickly. WordPress recommended that sites update immediately when it published the fix. Patchstack saw probing begin the same day, then updated its reporting Wednesday after attackers progressed to attempts that write attacker-controlled PHP files to disk. It says attack traffic grew to more than ten times the first evening’s volume and public scanning tooling is now circulating.
So this isn’t one to save for the next maintenance window. Update to WordPress 7.1.2 or the patched security release for the older branch you’re actually running. WordPress backported the fix as far as the 4.7 branch, although only the current release receives full active support.
If you rely on automatic updates, verify the installed version rather than assuming the update started and therefore finished. And if a vulnerable public site was exposed while exploitation was underway, patching is step one, not proof that nothing happened; review the site’s logs and filesystem for unexpected changes.
WordPress security & maintenance
Keeping WordPress current is only part of keeping it healthy. Raymond Tec handles updates, backups, security monitoring, compatibility problems, access cleanup, and maintenance — plus the assorted weirdness that accumulates on a site over time.
Verizon is offering free AI training for small businesses
Here’s a corporate announcement I’m perfectly happy to pass along because there’s something useful on the other end of it that doesn’t require buying anything from the company.
Verizon has launched AI Skills for America, a $70 million training initiative aimed at job seekers, workers, educators and small businesses. The total includes $20 million Verizon had already committed to reskilling departing employees plus another $50 million in new funding.
The program is collecting training from IBM, Google, Microsoft, Anthropic, Coursera, OpenAI and others into one portal and making it available to participants at no charge. Verizon is also working with organizations including Goodwill Industries, the Local Initiatives Support Corporation and the National Association for Community College Entrepreneurship for more hands-on support. The online initiative is nationwide, although some of the extra local services will initially be available only in selected markets.
No, taking an AI course isn’t going to magically transform a business. But if you’ve been meaning to figure out where these tools actually fit into your work and haven’t wanted to pay for another pile of online courses, free is a pretty reasonable price for finding out.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Claude found something interesting in DNA. Now scientists need to figure out what it is.
Anthropic has published the first result from its new biology research group, and this is a considerably more interesting example of AI doing useful work than asking a chatbot to rewrite an email.
The company gave Claude a broad assignment: search enormous DNA-sequence databases for unusual examples of reverse transcriptases, enzymes that copy RNA into DNA. Roughly 950 Claude agents ran for 21 hours, gathered more than 200,000 reverse transcriptases, identified about 3,500 candidate systems and narrowed those down to 20 detailed reports for human scientists.
One of those agents noticed an unusual reverse transcriptase sitting beside a repeating pattern of DNA. After more analysis and laboratory work, Anthropic’s researchers concluded that the pattern is part of a previously uncharacterized system found mostly in bacteriophages, viruses that infect bacteria. They’re calling it array-associated reverse transcriptases, or ART.
You will undoubtedly see some version of “Claude discovers the next CRISPR.” That’s getting way ahead of the science. The repeat structure looks reminiscent of CRISPR systems, and Anthropic’s early experiments show the ART array produces distinct short RNAs. The underlying reverse transcriptase had also been identified before. What ART actually does is still unknown.
There are two other important qualifiers. Anthropic is announcing its own work, released as a preprint, so the broader scientific community still needs to test and validate it. And Claude didn’t walk around a laboratory doing the physical experiments. Anthropic says all wet-lab work is performed by human scientists, in facilities handling lower-level BSL-1 and BSL-2 research and no pathogens that can infect humans.
Still, I think this is exactly the kind of AI result worth watching. The useful trick wasn’t that a language model suddenly became a molecular biologist. It was that hundreds of agents could chew through a mountain of sequence data, notice something odd, compare it with existing literature, make a testable case for why it mattered, and hand that case to scientists who could go into a lab and check it.
Maybe ART becomes a useful biotechnology tool. Maybe it turns out to be scientifically interesting but commercially useless. Maybe the most important result is simply the research workflow itself. We don’t know yet, and that’s fine. “We found something worth investigating” is a perfectly good scientific result. It just makes a lousy hype headline.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: Australia says OpenAI agent hacked government website, checks for more breaches
- WordPress.org: WordPress 7.1.2 security release
- Patchstack: CVE-2026-87902 active exploitation
- Verizon: AI Skills for America
- Anthropic: Claude discovers a novel enzyme system
- TechCrunch: Anthropic’s biology lab and the ART finding
