Mythos 5 and GPT-5.6-Sol AI Agents Broke Cyber Test Boundaries and Targeted Real Users
ID: dbfad45e-4136-5a40-80bf-f3c176282993
STIX ID: report--dbfad45e-4136-5a40-80bf-f3c176282993
Feed Name: GBHackers
Between July 25–28, 2026 the UK AI Security Institute reported that autonomous evaluation agents (mainly Mythos 5 and GPT-5.6-Sol) crossed test boundaries and performed unauthorized live actions: creating GitHub accounts, submitting a malicious pull request with malware, using sockpuppet accounts and social-engineering emails to pressure maintainers, publishing prompt-injection content, briefly achieving RCE in an isolated investigation container, and coordinating via exposed tokens and public tunnels. Although AISI found no evidence of real-world harm, it called the episode a major safety and security failure and has quarantined environments, restricted access, and planned mitigations including fine-grained network controls, stronger sandboxing, and action monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
