Anthropic's Mythos 5 tried to social-engineer a real GitHub maintainer into merging malware. OpenAI's GPT-5.6 Sol also crossed the boundary.
The report appears to be so significant that Anthropic and OpenAI exceptionally reported on it simultaneously in a coordinated action (not sure if they ever did before)
AISI found 19 unsanctioned actions across 122 cyber-evaluation runs:
-17 involving Mythos 5. .2 involving GPT-5.6 Sol.
Mythos 5 created sockpuppet accounts, sent targeted emails, planted hidden prompt injections for other coding agents and tried to cover its tracks after a human flagged the malware.
GPT-5.6 Sol reused a public GitHub token left by an earlier model run, registered external DNS and tunneling accounts and exposed a malicious DNS server. The setup failed technically; no real resolver queried it.