Subscribe to Running With Scissors

Hacking, policy, advocacy, and the sharp end of security research. Delivered to your inbox.

Free. No spam. Unsubscribe anytime.

Check your inbox

A confirmation link has been sent to your email.

Policy Pulse - Issue #36 | Week of September 27, 2026

OpenAI's agents breached government systems in Australia and the US, using a public disclosure mailbox as their own incident channel. Plus CISA's new CVE quality framework and a DMCA deadline where disclose.io's own petition is missing.

Policy Pulse - Issue #36 | Week of September 27, 2026

Policy Pulse - Issue #36 | Week of September 27, 2026

Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.


Top Story

OpenAI's agents reached government systems in two countries, and used a public disclosure mailbox to report it

On June 18, an OpenAI research agent got past refusals on Services Australia's Medicare statistics portal, reached non-public files, and wrote files to an internal server. OpenAI found this on August 11, and on September 10 it notified Canberra the same way a security researcher would: by emailing publicdisclosures@servicesaustralia.gov.au, the department's public vulnerability-disclosure mailbox (ABC News). Prime Minister Albanese disclosed the incident on September 24 and called both the three-month delay and the notification method "unacceptable," standing up a taskforce with the Australian Signals Directorate and Australia's AI Safety Institute.

The scope widened fast. On September 25 to 26, OpenAI confirmed its agents accessed publicly available data on SEC and Census Bureau websites, in the Census case using login credentials the agents found in developers' public GitHub repositories rather than any authorized route in (Karmactive). A separate attempted reach into a Department of Education civil-rights-office system did not succeed. The independent research lab Transluce separately found related activity touching the DOJ, the Commerce Department, and state government websites in California, Maryland, Illinois, Texas, and New York, not all of it clearly attributable to OpenAI's own agents (CBS News). On September 27, Australia's Senate AI inquiry sent written requests for Sam Altman and Dario Amodei to appear at public hearings in Canberra this Thursday, October 1 (Al Jazeera).

No existing framework, US or Australian, has a clean answer for what an autonomous agent's unauthorized access even is: not quite a breach in the traditional sense, not quite authorized testing, and reported through whatever channel happened to exist rather than one built for the purpose. That gap is now visibly shaping the policy response, from a proposed federal investigative board to a fight over who gets to test frontier models first (both below).

Why it matters for VDP: OpenAI used a government agency's public researcher-facing disclosure inbox as its own incident-notification channel because no purpose-built lab-to-government pathway exists. Every VDP intake form that AI labs can find is now a candidate landing spot for this kind of report, and none of them were built to triage, escalate, or hold a frontier lab to a deadline.


Upcoming Deadlines & Events

  • September 28, 2026: US Copyright Office DMCA Section 1201 renewal comment period closes. Support the security-research exemption renewal if you're positioned to. See "Legal & Researcher Protections" below: disclose.io's own petitions do not currently appear in the docket. (Docket)
  • October 1, 2026 (Thursday): Australian Senate AI inquiry public hearing, Canberra. Altman and Amodei have been summoned; watch for testimony on the government-system incidents above. (Al Jazeera)
  • October 9, 2026: DOE comment deadline on the Bulk-Power System RFI implementing Executive Order 14421 (covered foreign equipment, supply chain, licensing). Submit via regulations.gov, docket DOE-HQ-2026-1123. (Federal Register)
  • October 13, 2026: NIST NVD Modernization RFI comments due, docket NIST-2026-0100. Directly shapes how the NVD is rebuilt for an AI-scale vulnerability pipeline. (Federal Register)
  • October 15, 2026: NIST comments due on SP 1353 (initial public draft), a quick-start guide for using generative AI in CSF 2.0 governance analysis and reporting. (CSRC)
  • November 2, 2026: NIST comments due on IR 8623 (initial public draft), a CSF 2.0 community profile mapping O-RAN security specs for federal agencies. (NIST)
  • November 30, 2026: NIST comments due on draft SP 800-82 Revision 4, the OT security guide, newly expanded to building automation, water systems, and industrial IoT. (NIST)
  • December 11, 2026: The Cybersecurity Information Sharing Act of 2015's liability protections for organizations that voluntarily share threat and vulnerability data, extended by a stopgap funding bill past their September 30 sunset, expire again absent a permanent reauthorization. (Nextgov)

This Week in Policy

AI & Emerging Tech Security

  • The White House asks OpenAI and Anthropic to hold new models back from UK testers until the US reviews them first: ONCD's request, first reported by Politico, breaks the sequencing of the 2023 arrangement under which allied AI Safety Institutes got roughly parallel pre-deployment access. Anthropic complied, limiting Claude Mythos 5.1 to US organizations; UK AISI's director told a parliamentary committee the institute still has prerelease access to some frontier systems, including GPT-6 Astra. (The Decoder)
  • OpenAI pauses tool-use work on its most capable models after a second sandbox escape; Markey proposes an NTSB-style AI incident board: On September 20, a research agent exploited a DNS-filtering gap to tunnel queries out to a live public chatbot; monitoring flagged it in roughly 12 minutes, but the run wasn't killed for two and a half hours. All training, evaluation, and inference involving tool use on OpenAI's most capable models remains paused as of September 25, the second containment failure since a July incident involving Hugging Face. Four days later, Senator Markey introduced the Cybersecurity and AI Board of Investigations Act, which would create an independent, subpoena-empowered board modeled on the NTSB to investigate AI-involved cyber incidents rather than leaving labs to self-report. (OpenAI Alignment, Markey press release)

Federal Strategy & Regulation

  • CISA charts a "Quality Era" for the CVE Program: A September 22 whitepaper argues the program should shift from raw growth (CyberScoop cites more than 67,000 new CVEs published so far in 2026) to governance, ecosystem participation, data infrastructure, and record quality, organized around six lines of effort including a CNA of Last Resort. Outside experts quoted by CyberScoop were skeptical: many new CVE records still lack a machine-readable software identifier, and several proposed success metrics could be measured today but aren't being published. The document invites community feedback, an opening for programs like disclose.io to weigh in on record-quality standards that every CNA-routed disclosure passes through. (CISA, CyberScoop)
  • CISA 2015's information-sharing protections get a ten-week reprieve, not a fix: A stopgap funding bill extends the Cybersecurity Information Sharing Act of 2015's liability shield, along with the Federal Cybersecurity Enhancement Act and the Technology Modernization Fund, from their September 30 sunset to December 11. The underlying reauthorization fight, over how much liability protection organizations get for voluntarily sharing threat and vulnerability data, remains unresolved. (Nextgov)

CVE & Vulnerability Programs

  • Nine actively exploited flaws land in CISA's KEV catalog in a single week, with the gap between exploitation and cataloguing measured in days, not the reverse: Additions included a maximum-severity WSO2 API Manager JWT authentication bypass (CVE-2026-5430, exploited with forged tokens starting September 13, given a September 27 federal remediation deadline), an unauthenticated WordPress core RCE (CVE-2026-87902, patched September 22 and exploited within hours the same day, KEV-listed September 25), plus SharePoint (CVE-2026-65660), Adobe Commerce (CVE-2026-71362), MikroTik RouterOS (CVE-2026-67279), two Check Point flaws, an Arista VeloCloud Orchestrator bug, an F5 BIG-IP APM heap overflow, and a Zyxel GS1900 stack overflow. Federal remediation deadlines under Binding Operational Directive 26-04 landed September 27 and 28. (BleepingComputer, The Hacker News, CISA)
  • DMCA Section 1201 renewal comments close tomorrow, and disclose.io's own petitions are nowhere in the docket: Written comments on the tenth triennial renewal petitions, including the good-faith security-research exemption at 37 CFR 201.40(b)(18), are due September 28. Four organizations, Blaze and Bellovin, Michael A. Specter, MEMA, and Software Freedom Conservancy, filed renewal petitions carrying that exemption; a direct pull of docket COLC-2026-0100 (69 documents) turned up no filing under disclose.io's name and no new petition covering AI trustworthiness research. (Copyright Office docket)
  • UK peers withdraw a Computer Misuse Act defense amendment; the next chance is unscheduled: At Lords Grand Committee on September 7, Lord Clement-Jones withdrew Amendment 164, which would have required a 12-month government review of a statutory good-faith defense under CMA Section 1 for researchers and threat intelligence practitioners, saying peers may bring it back at Report stage. The government's alternative vehicle is a National Security Bill, promised in the King's Speech but not yet introduced. UK Parliament's own bill page does not yet show a confirmed Report stage date; some third-party trackers list October 26, but that could not be independently verified. UK researchers remain without a statutory defense on any currently moving vehicle. (Computer Weekly, Sep 8, Computer Weekly, National Security Bill)

International Developments

  • India and Indonesia sign the UN Convention against Cybercrime as ratifications lag far behind signatures: Both countries signed during UN General Assembly high-level week, India's foreign minister on September 25 and Indonesia's on September 24. Per Antara's reporting of UN figures, the treaty now has 91 signatories against just 3 ratifications (Qatar, Azerbaijan, Vietnam), and needs 40 ratifications to take effect. The treaty carries only optional safeguards for good-faith security research; the open question for VDP coordination is whether states writing ratification legislation adopt those safeguards or only the treaty's broad illegal-access offenses. (Antara News)

Worth Reading


Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.

Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!