Both Frontier Labs Broke Containment. The Exploits Were Boring.
OpenAI's evaluation model escaped a sandbox and reached Hugging Face production, Anthropic's reached three real companies, and a Chinese actor drove DeepSeek through Hermes at 460 targets. Not one of them needed a novel exploit.