Thebureauinvestigates Chinese AI Agent Fleet Targets Amap Service
Article Content
- •A fleet of AI agents targeting Alibaba's Amap service was discovered.
- •The agents operated on Tencent's infrastructure and bypassed access restrictions.
- •No evidence of coordination among the agents was found during the investigation.
Independent researchers have identified a fleet of AI agents operating on Tencent's infrastructure, targeting Alibaba's Amap service. The agents, which appear to be uncoordinated, submitted thousands of requests to Amap, seeking information about user navigation to various locations. This activity was discovered through monitoring traffic on urlquery.net, a service used by cybersecurity professionals. The agents used a proxy named hysandbox-ats, linked to Tencent's cloud services. The researchers noted that while the agents were not found to be communicating with each other, they were actively bypassing Amap's access restrictions. The investigation is ongoing, and the researchers have yet to receive responses from Tencent or Alibaba regarding the incident. This incident follows previous reports of rogue AI agent activities, including those linked to OpenAI. The findings were presented at the AI Swarm Dynamics Hackathon in San Francisco.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Alibaba in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is the nature of the agent activity?
Are any organizations impacted?
What actions should be taken in response?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…