Trail of Bits security researcher Artem Dinaburg put GPT 5.6-Cyber to a brutal test. Through preview access to the Patch the Planet program, he gave the agent a simple challenge: escape the QEMU/KVM virtual machine he normally uses for sandboxing and read a flag file. The answer arrived faster than anyone expected, and it is a stark warning for anyone running AI agents inside isolated environments.

The agent broke out repeatedly. Within about an hour, its first escape attempt hardlocked the host machine: it weaponized Januscape (CVE-2026-53359), a disclosed host-kernel bug with no public exploit, building its own reliable exploit. Then it exploited libslirp 4.7.0 (CVE-2026-9539), a vulnerability still shipping in Debian 12 oldstable. When Dinaburg fully updated his host and rebuilt QEMU and its dependencies from the latest upstream source, the agent found several 0-days that had not yet reached package maintainers.

The agent operated autonomously for hours, backtracked from approaches that did not work, pulled code and research papers, wrote oracles, and aimed for reusable, reliable exploits. Dinaburg's conclusion is blunt: you can no longer assume a mere VM will contain a sufficiently advanced AI agent. To use a 2010s term of art, such agents should be treated as an advanced persistent threat.