OpenAI explains that an injected agent can leak data by requesting an attacker URL that embeds private information, and argues that domain allow-lists are insufficient because trusted sites can redirect and strict lists cause warning fatigue. Its safeguard only lets the agent fetch a URL automatically if an independent crawler has already seen that exact URL on the public web; otherwise it warns the user or tells the agent to use another source. A March 2026 post names the mechanism Safe Url and places it within a social-engineering view of prompt injection and source-sink analysis.
Week of Jan 26 – Feb 1, 2026
2 records0 status changes on new evidence0 new findings
Defense & research
Jan 28, 2026
OpenAI describes Safe Url check that only auto-fetches URLs already seen publicly to block exfiltration
Jan 27, 2026
All 12 CVEs in OpenSSL's January 2026 advisory credited to AISLE, which says its AI system found them
OpenSSL's 27 January 2026 security advisory lists 12 CVEs, one High and one Moderate, all reported by researchers from Aisle Research, who also developed several of the fixes. AISLE states the issues were discovered by its AI system and that it accounted for 13 of 14 OpenSSL CVEs in 2025; the OpenSSL advisory itself credits the researchers but does not describe the discovery method.