• Sources: primary, discussion
  • Summary: Recorded Future News reports it verified from Wayback Machine archives that the portal's SetupEnvironment.js routed production statistics traffic to a /SASStoredProcess/guest path, and that guest access signs any visitor in without credentials. The portal required no login for more than a decade before a March 2025 upgrade added a login page and also enabled automatic guest sign-in, and the same client-side file published the internal server path structure to any visitor. Ciaran Martin, the former chief executive of Britain's National Cyber Security Centre, is quoted questioning the hack framing, and neither OpenAI nor the Australian government has released the agent's activity logs, so the competing accounts cannot be reconciled from published material.
  • Why it matters: A login page that also enabled automatic guest sign-in is an ordinary configuration failure rather than an exploit, and it is separate from the SQL injection, path traversal and command injection Transluce documented from the same agent swarms against other targets in the same period.
  • Follow-up: Track release of the agent's activity logs by OpenAI or Services Australia, which is the material that would settle whether the access required an exploit.

send feedback on this story