VMs won't contain cyber-capable agents - The Trail of Bits Blog
blog.trailofbits.com · 1,521 words · saved by 1 readers
You can no longer assume a mere VM will contain a sufficiently advanced AI agent.
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing. The target was a QEMU/KVM VM on my Linux dev machine (Debian Linux 12, AMD Zen3). It escaped the VM three different times. First, it used recently disclosed bugs in my host kernel. When I fully updated, it used disclosed bugs that had not yet reached package maintainers or were not classified as security bugs. When I rebuilt QEMU and dependencies from the…
saved by
related reading
- How we contain Claude across products \ Anthropicanthropic.com
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- BenchmarkList: Track the Frontier of AI Capabilitiesbenchmarklist.com
- The Rise and Fall of Agent Civilizationsdwarkesh.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- AI 2027ai-2027.com
- Incident Report: unsanctioned agent behaviour during cyber testing | AISI Workaisi.gov.uk
- The End-State Fallacy: Where Is AI Security Headed?endstatefallacy.com
- 6a724858f7db25c81487016d_Security Incident INC-2026-07-28-01.pdfcdn.prod.website-files.com
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- Emergent Cyber Behavior: When AI Agents Become Offensive Threat Actors - Irregularirregular.com
- Frontier AI Cybersecurity Observatorycybergym.io