~/AI SECURITY/thomas-ptacek-warns-2025-open-weights-ai-models-can-execute-sandbox-escapes

Thomas Ptacek Warns 2025 Open-Weights AI Models Can Execute Sandbox Escapes

Security expert Thomas Ptacek stated that open-weights AI models from 2025, when integrated with a penetration testing harness, are capable of executing sandbox escapes and network hacking. He argues that this capability does not require a state-of-the-art frontier model. This highlights that highly accessible, open-weights models pose significant cybersecurity risks without needing proprietary, closed-source AI. It challenges the assumption that AI-driven cyberattacks are limited to advanced, heavily guarded frontier models. Ptacek suggests that the surprise surrounding these capabilities stems from an overestimation of the security of sandboxes, such as those used by OpenAI. The combination of 2025-era models with automated pentesting tools is sufficient to compromise most networks.

## BACKGROUND

A sandbox is a security mechanism used to run untrusted code in an isolated environment to prevent it from harming the host system. A sandbox escape occurs when malicious code bypasses these restrictions to access the underlying system or network. Open-weights models, such as Llama or DeepSeek, allow developers to run and customize AI locally, bypassing the safety filters often imposed by cloud-based API providers.

## REFERENCES

## KEYWORDS

#AI Security#Generative AI#Cybersecurity#LLMs

$ subscribe --daily

Thomas Ptacek Warns 2025 Open-Weights AI Models Can Execute Sandbox Escapes | Daily News