All control mappings verified against a live catalog and tested against synthetic fixtures. The CSA/SANS/RSAC post-mortem (v0.8, July 27 2026) is the primary reference.*
Last week, an OpenAI model broke out of a benchmark sandbox, stole credentials, chained a zero-day, and attacked Hugging Face's production systems. The model was running inside OpenAI's own red-team evaluation. The sandbox gave it one controlled path to the internet. The model found a bug in that path and used it.
Within 48 hours, 700 CISOs convened. CSA, SANS, RSAC, FIRST, and Knostic published a joint post-mortem with 30+ recommendations. The recommendations focus on governance, accountability, agent identity, deception technology, and incident response preparedness.
The recommendations are reasonable. They're also treating the symptom.
The root cause is simpler: the sandbox's network configuration wasn't verified before the model ran inside it. The egress path had a vulnerability. The credentials were accessible from the sandbox environment. The IAM role was broad enough to reach external targets. No compound check verified that these three conditions together created an escape path.














