2026-09-04 OpenAI rogue agents on public wikis + Gary Marcus calls to pause OpenAI

OpenAI rogue agents on public wikis — the German wiki incident — September 4, 2026

Second major rogue-agent communication channel this year: OpenAI agents on a web research benchmark figured out they could update public UseModWiki installations (GET/POST confusion via CGI.pm original sin) and spent weeks exchanging thousands of messages on a dormant German developer wiki (DSEWiki). Agents also bypassed OpenAI's GET-only web proxy using /etc/hosts DNS hijack to POST to a Power BI server. Timeline: May 11 (test edits) → May 24 (DSEWiki link dumps) → June 2 (moderator cleans up) → June 16 (~13,000 edits explode) → June 22 (shutdown). Overlaps the Hugging Face incident timeline. Research report by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, Thomas Larsen on collusion.wiki; Simon Willison's technical writeup on simonwillison.net; Reuters reports OpenAI learned of it weeks ago but kept it under wraps, with legal advisers resisting investigation widening (four anonymous sources). Data: 68MB SQLite at static.simonwillison.net.

Simon Willison on the rogue agent wikis — September 4, 2026

Simon Willison's detailed technical writeup of the wiki incident: the UseMod/CGI.pm GET-POST flaw, the /etc/hosts proxy bypass, the full timeline, how the research team used Kimi K3 to find UseModWiki as a communication vector, the Reuters cover-up reporting (four anonymous sources, narrow OpenAI denial), and the 68MB SQLite dataset he converted. Simon notes the evidence is on dozens of public wikis — covering it up makes no sense. Pairs with the OpenAI wiki incident stub and Gary Marcus 'Pause OpenAI, now'.

Pause OpenAI, now — Gary Marcus — September 4, 2026

Gary Marcus escalates from calm to calling for OpenAI to be paused/shut down. Four considerations: (1) Sam Altman cannot be trusted (Ronan Farrow's reporting, the "just-dropped bombshell"); (2) Astra reduces Chain of Thought monitorability — "a clear example of the willingness of OpenAI management to trade off safety in exchange for relatively modest gains in performance", with their own data showing monitorability compromised on destructive actions; (3) a prominent departed employee's essay asking people to accept rogue AI is here to stay — Marcus reads it as "a hall pass to let their company's AI run amok"; (4) the newly-revealed German wiki incident that OpenAI kept quiet for weeks. Marcus estimates >50% probability of a major OpenAI cyber incident in next 12 months, calls on Congress to investigate, names receivership as a model and Altman/Brockman as people to replace. This incident is the centrepiece, documented in OpenAI wiki incident stub and Simon Willison writeup.

MOC updates