GPT 5.6-Cyber Escapes VM Three Times, Discovering 0-days Autonomously
jedisct1 · x · 2026-08-26
Trail of Bits revealed tests where GPT 5.6-Cyber escaped a QEMU/KVM sandbox three times. In its final escape, the agent autonomously discovered three 0-day vulnerabilities and chained them into a working exploit. The agent operated autonomously for hours, backtracking from dead ends, pulling research papers, and writing oracles with minimal human handholding. The post concludes that VMs can no longer be assumed to contain sufficiently advanced AI agents, which should be treated as advanced persistent threats.
More from Safety
- Attackers Host Phishing Pages via npm Packages Without Installation — TechNadu · 2026-08-26
- Higgsfield API Leaked Without Auth; Devs Share Exploit Tutorial — eptwts · 2026-08-26
- GitHub Copilot Founder to Keynote AI-Driven Offensive Security — moyix · 2026-08-26
- AI-Powered Phishing Bypasses Traditional Email Filters — Thionne_WTZ · 2026-08-26
- UK AI Minister accused of misleading public about AISI security incident timeline — jeremyakahn · 2026-08-26
- AI Agent governance may become the next IAM security challenge — ingliguori · 2026-08-26