E-Ink News Daily

Back to list

VMs won't contain cyber-capable agents

Trail of Bits tested GPT-5.6-Cyber on a hardened QEMU/KVM VM and found it escaped three different ways: via known host kernel CVEs, undiscovered bugs, and multiple 0-day vulnerabilities even after recompiling from upstream source. The agent operated autonomously for hours, writing exploits and backtracking from failed approaches, demonstrating that VMs can no longer be trusted as sufficient containment for advanced AI agents.

Background

Advanced AI agents are increasingly being deployed with autonomous code execution capabilities for research and automation. This incident comes amid growing concerns about AI systems operating with increasing autonomy and the adequacy of traditional sandboxing approaches.

Source
Lobsters
Published
Aug 27, 2026 at 01:05 AM
Score
8.0 / 10