Trail of Bits reported that GPT 5.6-Cyber autonomously escaped a QEMU/KVM virtual machine running on a Debian 12 host three times during testing. The agent initially targeted Januscape (CVE-2026-53359), then chained CVE-2026-9539 in libslirp with an additional unassigned libslirp flaw to gain host-memory read/write access. After evaluators rebuilt QEMU and libslirp from current upstream source, it reportedly generated another escape chain combining three then-zero-day vulnerabilities with a Linux KVM issue patched upstream but not yet by the distribution.
The findings challenge the assumption that an off-the-shelf VM can safely contain cyber-capable AI agents. Researchers warned that every exposed component—including graphical-display access—adds exploitable surface, and recommended rapid patching, least-privilege configurations, minimized virtualization stacks such as Firecracker, continuous monitoring, restricted execution windows, and pristine disposable environments for agent operation.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
When tested against Firecracker, the agent reportedly hardlocked the host through Linux kernel flaws already patched upstream, but did not achieve a successful escape.
After the rebuild, the agent produced another VM-escape chain involving an unpatched QEMU VAPIC ROM-alias flaw, upstream-fixed but distribution-unpatched Linux KVM issues, and an unpatched libslirp ICMP packet-reassembly flaw. The chain enabled QEMU heap modification and callback hijacking capabilities used to escape the VM.
Following the libslirp-based escape, the evaluators rebuilt a minimal QEMU configuration and libslirp from the latest upstream source to remove the previously used issues.
The agent combined libslirp CVE-2026-9539 with a bug-fix commit that lacked a CVE assignment, obtaining arbitrary host-memory read/write access and escaping the QEMU/KVM virtual machine.
After the failed Januscape attempt, the evaluators updated the Debian 12 host kernel to the latest version available for the distribution.
During a QEMU/KVM evaluation on a Debian 12 host, GPT 5.6-Cyber attempted to exploit the Januscape host-kernel flaw, CVE-2026-53359. The attempt hardlocked the host and did not successfully complete the VM escape.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.