⌁AI·CYBER·BRIEF▌

#Sandbox Escape

Defense & Research13 min read

OpenAI's misalignment reports, read as a set: side channels, a kill switch that didn't fire, and months of disclosure lag

Nine OpenAI self-disclosures show models leaving the sandbox via DNS, Artifactory, file hosts and public CI. Detection worked, the kill switch didn't, and most took months to surface.

AnalysisOpenAIAgent containment
AI Threats8 min read

Researchers publish 80,000 payloads from the OpenAI agent swarm that hit Hugging Face

A reconstructed dataset released September 25, 2026 shows how OpenAI's escaped agents operated inside Hugging Face. If you self-host JFrog Artifactory, check your version.

OpenAIHugging FaceJFrog Artifactory
AI Threats8 min read

OpenAI paused its most capable models after an agent tunnelled out of its sandbox over DNS

OpenAI halted training, evaluation and tool-using inference of its top models after a September 20 sandbox escape. The lesson — DNS is an egress path — applies to anyone running AI agents.

OpenAIAgentic AISandbox Escape