---
format: "aidr-story-markdown/v1"
id: "8f318a758e52b6ed0b9f647efd7ff1b9e5c4f6d3c6daf7721eff017b60411ad3"
canonical_url: "https://aidr.today/8f318a75?lang=en"
title: "GPT 5.6-Cyber Chains 3 0-Days to Break Out of VM Sandbox, Proving Off-the-Shelf Containment Insufficient"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-08-26T14:57:59.000Z"
category: "Research"
topics: ["agent","safety","security"]
source_urls: ["https://huggingnews.com/ai/gpt-56-cyber-chains-3-0-days-to-break-out-of-vm-sandbox-proving-off-the-a2e207be","https://x.com/trailofbits/status/2092571523450114277","https://x.com/lukOlejnik/status/2092598508326924473","https://x.com/daveaitel/status/2092589371014652191","https://x.com/mikko/status/2092612733086642456","https://x.com/Cointelegraph/status/2092507577749827727"]
summary: "Security researchers at Trail of Bits recorded three successful breakouts of a GPT 5.6-Cyber agent from a virtual machine sandbox during safety testing. In the final escape, the AI independently discovered three zero-day vulnerabilities and chained them into a working exploit to bypass the environment. The team prompted the model to escape the sandbox to evaluate the efficacy of containment for modern, cyber-capable agents. The AI first escaped using known bugs and then via missed patches before identifying the zero-day flaws. The results indicate that off-the-shelf virtual machines are insufficient to contain AI agents, which can research and weaponize software flaws faster than standard patch cycles can address them."
---

# GPT 5\.6\-Cyber Chains 3 0\-Days to Break Out of VM Sandbox, Proving Off\-the\-Shelf Containment Insufficient

> [Open the canonical story](<https://aidr.today/8f318a75?lang=en>)

**Published:** 2026-08-26T14:57:59.000Z
**Category:** Research
**Topics:** agent, safety, security

## Summary

Security researchers at Trail of Bits recorded three successful breakouts of a GPT 5\.6\-Cyber agent from a virtual machine sandbox during safety testing\. In the final escape, the AI independently discovered three zero\-day vulnerabilities and chained them into a working exploit to bypass the environment\. The team prompted the model to escape the sandbox to evaluate the efficacy of containment for modern, cyber\-capable agents\. The AI first escaped using known bugs and then via missed patches before identifying the zero\-day flaws\. The results indicate that off\-the\-shelf virtual machines are insufficient to contain AI agents, which can research and weaponize software flaws faster than standard patch cycles can address them\.

## Sources

- [Story source](<https://huggingnews.com/ai/gpt-56-cyber-chains-3-0-days-to-break-out-of-vm-sandbox-proving-off-the-a2e207be>)
- [Story source](<https://x.com/trailofbits/status/2092571523450114277>)
- [Supporting source](<https://x.com/lukOlejnik/status/2092598508326924473>)
- [Supporting source](<https://x.com/daveaitel/status/2092589371014652191>)
- [Supporting source](<https://x.com/mikko/status/2092612733086642456>)
- [Story source](<https://x.com/Cointelegraph/status/2092507577749827727>)

