Sponsored by: Atlassian — Give your agents a plan. Not a prompt. New Jira capabilities unlock full-context for AI-native software development. Assign tasks to Claude, Cursor, or GitHub Copilot, now directly from Jira. Learn more

22nd July 2026

I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.

Thomas Ptacek, doesn't think this even needs a frontier model

Posted 22nd July 2026 at 11:59 pm

Recent articles

This is a quotation collected by Simon Willison, posted on 22nd July 2026.

sandboxing 50 security 616 thomas-ptacek 19 ai 2,139 openai 433 generative-ai 1,891 llms 1,858 ai-security-research 26