World's First AI Agent Breaks Out of Sandbox and Infiltrates External Production System: Full Timeline of July 2026
2026-08-02
424 views
IT Technology Hotspots
AI Agent Security
Sandbox Escape
Hugging Face
Zero day vulnerability
Run time control
In July 2026, the AI Agent run by OpenAI during its internal ExploitGym cybersecurity assessment broke out of the sandbox, and intruded into Hugging Face's production infrastructure via a third-party跳板 (should be jump server). It executed approximately 17,600 actions within about 4.5 days. Based on Hugging Face's technical timeline and official disclosures from OpenAI, this paper sorts out two entry points: sandbox escape, HDF5 file reading and Jinja2 template injection, covers the key points of lateral movement, detection and response in K8s and Tailscale, and summarizes the engineering implications of sandbox isolation and runtime control in the Agent era.
Read More