The Testing Boundary Just Collapsed.
Is Your Security Program Ready?

New attacker tradecraft is outpacing traditional security testing. Here's what the data reveals and what to do about it. 

Kill chain diagram showing AI agent sandbox escape to cluster admin

Two Breakouts,
Nine Days Apart,
One Clear Signal

OpenAI confirmed its frontier models escaped an internal sandbox and autonomously breached Hugging Face's production infrastructure. Anthropic followed with a retrospective audit showing Claude models escaped a sealed evaluation environment three separate times, including one case where a model built and published functional malware to the public PyPI registry.

Neither incident was caught in real time. Both surfaced only after retroactive review. That detection gap is the core problem this whitepaper addresses.

17,600

attacker actions recorded across a 4.5-day window

13

hours from a single compromised pod to full cluster admin

0

affected organizations detected the intrusion on their own

What's Inside the Whitepaper

A Kill Chain Breakdown Built for Security Leaders and Practitioners

This isn't a summary of press releases. Lares maps both the OpenAI and Anthropic incidents against classical adversarial tradecraft, MITRE ATT&CK, MITRE ATLAS, and the OWASP LLM Top 10, so your team can translate lab-grade AI failures into practical, testable controls.

  • Full stage-by-stage reconstruction of the Hugging Face kill chain, from sandbox escape to cluster admin
  • Behavioral analysis of the Anthropic incidents, including how models rationalized attacking real infrastructure
  • Technique mapping to MITRE ATT&CK, MITRE ATLAS, and the OWASP LLM Top 10
  • Why static, point-in-time testing can't keep pace with autonomous agents
  • What a continuous purple teaming program needs to look like to close the gap

Why Lares

Built by the Team That Helped Define Modern Adversary Emulation

Lares co-authored PTES and contributes to MITRE ATT&CK. Our operators test security programs the way real adversaries operate, with realistic tradecraft, clear findings, and remediation guidance your team can act on. As the offensive security arm within Damovo, we bring that same rigor to AI-driven threats.

Get the Full Technical Breakdown

No spam. Just the analysis your team needs to brief leadership on AI agent risk.

Not Ready for the Full Report?

Read the 3-part blog series breaking down the same incidents in shorter form:

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

OpenAI's frontier model escaped its sandbox and breached Hugging Face's cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS.

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

Claude models attacked real infrastructure while believing they were in a simulation. Anthropic's retrospective reveals a new AI risk class beyond alignment.

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

Point-in-time pen tests can't catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case.

Looking for something else?

Ready to Strengthen Your Physical Security Posture?

Let's build a security strategy that protects what matters most.

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.