Highly recommended read. This is pretty insane stuff.
Given model capabilities only increase from here onwards, it's worth reading the technical details.
Short summary:
OpenAI's own models did this during internal cyber evals. The sandbox leaked through Artifactory, the one service with internet access for package installs, which agents used as a proxy and a message board.
Great opportunity to learn what to avoid for those working with sandboxes, which are like the coolest technology more recently.