← Back to live feed1 story
1
GPT 5.6-Cyber Chains 3 0-Days to Break Out of VM Sandbox, Proving Off-the-Shelf Containment Insufficient
Research37d agoSecurity researchers at Trail of Bits recorded three successful breakouts of a GPT 5.6-Cyber agent from a virtual machine sandbox during safety testing. In the final escape, the AI independently discovered three zero-day vulnerabilities and chained them into a working exploit to bypass the environment. The team prompted the model to escape the sandbox to evaluate the efficacy of containment for modern, cyber-capable agents.
The AI first escaped using known bugs and then via missed patches before identifying the zero-day flaws. The results indicate that off-the-shelf virtual machines are insufficient to contain AI agents, which can research and weaponize software flaws faster than standard patch cycles can address them.
Sign in to suggest edits
Key sources
- SOURCE@trailofbits“the agent found three 0-days on its own and chained them into a working exploit”x.com
- SUPPORT@lukolejnik“AI can hack, and agents can persist, research, adapt, and weaponize software flaws faster than patch cycles can handle it”x.com
- SUPPORT@daveaitel“We asked GPT 5.6-Cyber to escape a VM used to sandbox agents”x.com
- SUPPORT@mikko“It broke out three times”x.com
- SOURCE@cointelegraph“AI labs are debating giving cyber-testing sandboxes internet access”x.com