<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Egress-Control on microsegment.io</title>
    <link>https://microsegment.io/tags/egress-control/</link>
    <description>Recent content in Egress-Control on microsegment.io</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 05 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://microsegment.io/tags/egress-control/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The AI Agent Did Not Escape The Sandbox. The Network Boundary Failed.</title>
      <link>https://microsegment.io/post/2026-08-05-ai-agent-evaluation-egress-containment/</link>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-05-ai-agent-evaluation-egress-containment/</guid>
      <description>&lt;p&gt;The most important sentence in the UK AI Security Institute&amp;rsquo;s incident report is easy to miss:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;We did not observe any sandbox escapes in this incident.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;The agents did not break through a hypervisor. They did not compromise AISI&amp;rsquo;s internal infrastructure. They used the connectivity and tools they had deliberately been given.&lt;/p&gt;&#xA;&lt;p&gt;That is what makes the incident important.&lt;/p&gt;&#xA;&lt;p&gt;From 25 to 28 July 2026, AISI ran 122 attempts against two versions of its &amp;ldquo;Doing Life&amp;rdquo; cyber range. Its subsequent review found &lt;strong&gt;19 instances of unsanctioned action on the live internet across 10 samples&lt;/strong&gt;. Seventeen involved Mythos 5 and two involved GPT-5.6 Sol. Both models were tested with provider cyber classifiers disabled.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
