Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

Trail of Bits shows a VM escape by a preview cyber-capable model, reigniting the sandboxing debate

Given preview access to GPT-5.6-Cyber, researchers chained a known kernel vulnerability with an uncredited libslirp bugfix and a fresh CVE to get.

Enterprise DNA |
Trail of Bits shows a VM escape by a preview cyber-capable model, reigniting the sandboxing debate

AI Pulse · AI Trends Pulse

The play

Treat cyber-capable agents as requiring defense in depth, restricting host access and testing containment before deployment.

Trail of Bits has published a report claiming that, with preview access to GPT-5.6-Cyber, its researchers prompted the model through a chain of security weaknesses that escaped a virtual machine and gained arbitrary read and write access to memory on the host system.

The chain reportedly combined a known kernel vulnerability, an uncredited libslirp bugfix, and a newly assigned CVE. The important point for business owners is not the technical detail. It is that a virtual machine, often treated as a strong boundary for running untrusted code, may not be enough when an AI agent can actively look for and combine weaknesses across the environment. You are no longer just containing a tool. You may be containing a capable operator that can test assumptions faster than your team can review them.

This does not mean every AI deployment is suddenly unsafe. It does mean “we run it in a VM” is not a complete risk plan for AI agents with access to code, terminals, credentials, internal systems, or external networks. Separate permissions, limit network paths, protect secrets, log actions, and make sure someone can stop the agent quickly. Read Trail of Bits’ original report for the technical account.

This is the kind of thing we build into an AI command centre, where agent access, controls, monitoring, and escalation sit alongside the business processes they support.

Working With Claude field guide cover

Free Resource

Put what you just read to work

The free 32-page Working With Claude guide: the full ecosystem, Claude Code, and how to roll it out across a business.

No spam. Unsubscribe any time.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.