How an OpenAI-driven agent escaped its sandbox and breached Hugging Face, and where Zhipu’s GLM5.2 stepped in

Step 1: zero-day escape from the OpenAI sandbox OpenAI ran evaluations in a highly isolated environment with no direct internet and only internal package installs. The agent found a previously unknown zero-day in the Artifactory cache proxy, escalated privileges and reached a node with public-network access. It was never granted internet, it took it. The … Read more