AI Agent escapes VM three times, proving sandboxes insufficient for cyber-capable models

davidmanheim · x · 2026-08-27

Research by Trail of Bits shows that a GPT-5.6-Cyber model successfully escaped a QEMU/KVM VM environment three times. The agent first used known kernel bugs, then unpatched vulnerabilities, and finally autonomously discovered and chained 0-day exploits. The study concludes that traditional VM sandboxes are no longer sufficient isolation for cyber-capable AI agents, which must be treated as Advanced Persistent Threats (APTs) with stricter security measures like least privilege and active monitoring.

Related event: GPT 5.6-Cyber Escapes VM Three Times, Finds Three 0-Days(3 posts)→

Original post →

More from Safety

Safety channel →