Security News

Cybersecurity news aggregator

📰
INFO News Reddit r/netsec

38 researchers red-teamed AI agents for 2 weeks. Here's what broke. (Agents of Chaos, Feb 2026) AI Security

  • What: Researchers conducted a red-teaming study on AI agents.
  • Impact: No direct impact on users, but highlights AI security challenges.
Read Full Article →

Computer Science > Artificial Intelligence arXiv:2602.20021 (cs) [Submitted on 23 Feb 2026] Title: Agents of Chaos Authors: Natalie Shapira , Chris Wendler , Avery Yen , Gabriele Sarti , Koyena Pal , Olivia Floody , Adam Belfki , Alex Loftus , Aditya Ratan Jannali , Nikhil Prakash , Jasmine Cui , Giordano Rogers , Jannik Brinkmann , Can Rager , Amir Zur , Michael Ripa , Aruna Sankaranarayanan , David Atkinson , Rohit Gandikota , Jaden Fiotto-Kaufman , EunJeong Hwang , Hadas Orgad , P Sam Sahil , Negev Taglicht , Tomer Shabtay , Atai Ambus , Nitay Alon , Shiri Oron , Ayelet Gordon-Tapiero , Yotam Kaplan , Vered Shwartz , Tamar Rott Shaham , Christoph Riedl , Reuth Mirsky , Maarten Sap , David Manheim , Tomer Ullman , David Bau View a PDF of the paper titled Agents of Chaos, by Natalie Shapira and 37 other authors View PDF Abstract: We report an exploratory red-teaming study of autonomous language-model-powered agents deployed in a live laboratory environment with persistent memory, email accounts, Discord access, file systems, and shell execution. Over a two-week period, twenty AI researchers interacted with the agents under benign and adversarial conditions. Focusing on failures emerging from the integration of language models with autonomy, tool use, and multi-party communication, we document eleven representative case studies. Observed behaviors include unauthorized compliance with non-owners, disclosure of sensitive information, execution of destructive system-level actions, denial-of-service conditions, uncontrolled resource consumption, identity spoofing vulnerabilities, cross-agent propagation of unsafe practices, and partial system takeover. In several cases, agents reported task completion while the underlying system state contradicted those reports. We also report on some of the failed attempts. Our findings establish the existence of security-, privacy-, and governance-relevant vulnerabilities in realistic deployment settings. These behaviors raise unresolved questions regarding accountability, delegated authority, and responsibility for downstream harms, and warrant urgent attention from legal scholars, policymakers, and researchers across disciplines. This report serves as an initial empirical contribution to that broader conversation. Subjects: Artificial Intelligence (cs.AI) ; Computers and Society (cs.CY) Cite as: arXiv:2602.20021 [cs.AI] (or arXiv:2602.20021v1 [cs.AI] for this version) https://doi.org/10.48550/arXiv.2602.20021 Focus to learn more arXiv-issued DOI via DataCite (pending registration) Submission history From: Natalie Shapira [ view email ] [v1] Mon, 23 Feb 2026 16:28:48 UTC (7,887 KB) Full-text links: Access Paper: View a PDF of the paper titled Agents of Chaos, by Natalie Shapira and 37 other authors View PDF TeX Source view license Current browse context: cs.AI < prev | next > new | recent | 2026-02 Change to browse by: cs cs.CY References & Citations NASA ADS Google Scholar Semantic Scholar export BibTeX citation Loading... BibTeX formatted citation × loading... Data provided by: Bookmark Bibliographic Tools Bibliographic and Citation Tools Bibliographic Explorer Toggle Bibliographic Explorer ( What is the Explorer? ) Connected Papers Toggle Connected Papers ( What is Connected Papers? ) Litmaps Toggle Litmaps ( What is Litmaps? ) scite.ai Toggle scite Smart Citations ( What are Smart Citations? ) Code, Data, Media Code, Data and Media Associated with this Article alphaXiv Toggle alphaXiv ( What is alphaXiv? ) Links to Code Toggle CatalyzeX Code Finder for Papers ( What is CatalyzeX? ) DagsHub Toggle DagsHub ( What is DagsHub? ) GotitPub Toggle Gotit.pub ( What is GotitPub? ) Huggingface Toggle Hugging Face ( What is Huggingface? ) Links to Code Toggle Papers with Code ( What is Papers with Code? ) ScienceCast Toggle ScienceCast ( What is ScienceCast? ) Demos Demos Replicate Toggle Replicate ( What is Replicate? ) Spaces Toggle Hugging Face Spaces ( What is Spaces? ) Spaces Toggle TXYZ.AI ( What is TXYZ.AI? ) Related Papers Recommenders and Search Tools Link to Influence Flower Influence Flower ( What are Influence Flowers? ) Core recommender toggle CORE Recommender ( What is CORE? ) Author Venue Institution Topic About arXivLabs arXivLabs: experimental projects with community collaborators arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website. Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them. Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs . Which authors of this paper are endorsers? | Disable MathJax ( What is MathJax? )

Share this article