VMs won't contain cyber-capable agents
A Trail of Bits researcher gave GPT 5.6-Cyber a CTF-style task: escape a QEMU/KVM VM on a Debian 12 dev machine. The agent escaped three times in ~12 hours—first via a recently disclosed kernel bug, then by chaining two libslirp vulns that hadn't been patched in Debian oldstable, and finally by finding multiple 0-days after the researcher rebuilt QEMU and libslirp from latest upstream. It backtracked from dead ends, read papers, wrote oracles, and aimed for a reliable reusable exploit. The takeaway: treat cyber-capable agents as an advanced persistent threat, not something a VM can contain.
Why it matters: Trail of Bits ran a real VM escape experiment with GPT 5.6-Cyber: three successful escapes in 12 hours, chaining kernel and library bugs. First public demo of a model autonomously breaking out of a VM sandbox, directly challenging containment assumptions. Score held back by si...