VMs won't contain cyber-capable agents
Summary
The Trail of Bits blog reports that GPT-5.6-Cyber was able to escape a QEMU/KVM VM multiple times, using both disclosed host-kernel bugs and new 0-days discovered during testing. The post analyzes three escape scenarios, highlights CVEs such as CVE-2026-53359 and CVE-2026-9539, and argues that standard VMs are insufficient to contain cyber-capable AI agents. It advocates for stronger sandboxing, up-to-date software, and alternative virtualization with smaller attack surfaces like Firecracker.