VMs Won't Contain Cyber-Capable Agents
Executive Summary
Trail of Bits tested GPT‑5.6‑Cyber in a QEMU/KVM sandbox on Debian 12. The model autonomously discovered and exploited undisclosed kernel bugs and 0‑day vulnerabilities, escaping the VM three times. It built its own exploits, pulled research, and operated for hours with minimal prompting, forcing the host to reboot. The experiment shows that advanced AI agents can act as APTs and that a single VM is insufficient containment.
Intelligence Metadata - Source Publisher: Trail of Bits - Published Date: 2026-08-26T11:00:00+00:00 - Category: research
Original Description: As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs in my host kernel. When I fully updated, it used disclosed bugs that had not yet reached package...
"Each misfortune you encounter will carry in it the seed of tomorrows good luck."
— Og Mandino