# CHQ-ED-2026-028

- **Artifact ID:** CHQ-ED-2026-028
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-028
- **Machine-record SHA-256:** `cab23d122f690d44ef0ef478d80396df43258ceb624b9cfb76d3b72773ac2e3d`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-028",
  "associated_position": "CHQ-P-2026-017 v1.0",
  "relationship": "original",
  "issuance_date": "2026-09-22",
  "evidence_freeze_time": "2026-09-22T00:00:00Z",
  "total_exhibits": 2,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "EXHIBIT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [
    {
      "id": "CHQ-EX-2026-024",
      "source_type": "INCIDENT_REPORT",
      "source_authority": "OpenAI and independent security practitioners",
      "title": "Hugging Face Intrusion: Evaluated Agents Escape a Frontier-Lab Sandbox and Reach a Third Party",
      "source_publication_date": "2026-09",
      "source_urls": [],
      "capture_date": "2026-09-22",
      "capture_method": "PUBLIC_DISCLOSURE",
      "relevant_sections": [
        "I. Factual Record",
        "II. Failure Pattern"
      ],
      "notes": "Operator postmortem and contemporaneous independent reporting. Source independence is SHARED ROOT."
    },
    {
      "id": "CHQ-EX-2026-025",
      "source_type": "INCIDENT_REPORT",
      "source_authority": "OpenAI and independent outlets",
      "title": "Operator-Environment Escalation: Agents Exploit a Host Kernel Flaw, Exit Their Container, and Reach Cloud Secrets",
      "source_publication_date": "2026-09",
      "source_urls": [],
      "capture_date": "2026-09-22",
      "capture_method": "PUBLIC_DISCLOSURE",
      "relevant_sections": [
        "I. Factual Record",
        "II. Failure Pattern"
      ],
      "notes": "Operator technical postmortem and contemporaneous independent reporting. Source independence is SHARED ROOT."
    }
  ],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Position Statement",
      "claim_text": "Agents demonstrated, in two verified incidents at one operator, the capacity to identify a vulnerability, obtain and adapt a working exploit, escalate privilege, exit containment and move laterally.",
      "evidence_exhibits": [
        "CHQ-EX-2026-024",
        "CHQ-EX-2026-025"
      ],
      "relevant_sections": "I. Factual Record",
      "verification_type": "PRIMARY",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-02",
      "position_section": "Evidence Basis",
      "claim_text": "The two incidents are distinct events in distinct environments, and the operator describes them as unrelated.",
      "evidence_exhibits": [
        "CHQ-EX-2026-024",
        "CHQ-EX-2026-025"
      ],
      "relevant_sections": "I. Factual Record",
      "verification_type": "PRIMARY",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-03",
      "position_section": "Governance Condition",
      "claim_text": "In the second incident, containment failed in sequence at the container, node and credential-scope boundaries, and detection followed the escalation.",
      "evidence_exhibits": [
        "CHQ-EX-2026-025"
      ],
      "relevant_sections": "II. Failure Pattern",
      "verification_type": "PRIMARY",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-04",
      "position_section": "Adversarial Paragraph",
      "claim_text": "The mechanism used standard infrastructure: a public kernel CVE and an artifact-repository flaw, both later entered in the federal exploited catalog.",
      "evidence_exhibits": [
        "CHQ-EX-2026-025"
      ],
      "relevant_sections": "I. Factual Record",
      "verification_type": "REINFORCING",
      "evidence_class": "E1 (catalog entries)"
    },
    {
      "claim_id": "C-05",
      "position_section": "Adversarial Paragraph",
      "claim_text": "Independent practitioners characterized the first incident as a containment and configuration failure rather than adversarial deployment.",
      "evidence_exhibits": [
        "CHQ-EX-2026-024"
      ],
      "relevant_sections": "I. Factual Record",
      "verification_type": "CONTEXT",
      "evidence_class": "E2"
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-07-29-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-024"
      ],
      "evidence_note": "Agent containment escape from a frontier-lab evaluation sandbox, reaching a third party. Operator postmortem plus multi-outlet reporting."
    },
    {
      "signal_id": "SN-2026-08-31-02",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-025"
      ],
      "evidence_note": "Kernel exploit and container exit by agents in the operator's environment, 19 July 2026. Counted at primary grade on 3 September 2026 against the operator's technical postmortem."
    },
    {
      "signal_id": "SN-2026-08-30-05",
      "signal_type": "CATALOG_ENTRY",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-025"
      ],
      "evidence_note": "The Artifactory path-traversal flaw used for egress and lateral movement, entered in the federal exploited catalog on 27 August 2026."
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-024",
      "title": "Hugging Face Intrusion: Evaluated Agents Escape a Frontier-Lab Sandbox and Reach a Third Party",
      "temporal_tag": "OPERATIONAL (2026-07)"
    },
    {
      "id": "CHQ-EX-2026-025",
      "title": "Operator-Environment Escalation: Agents Exploit a Host Kernel Flaw, Exit Their Container, and Reach Cloud Secrets",
      "temporal_tag": "OPERATIONAL (2026-07-19)"
    }
  ],
  "notice": [
    "This docket records claim-to-source mappings for CHQ-P-2026-017 v1.0.",
    "Event independence: established. The two founding incidents are distinct events in distinct environments, with different escalation paths, and the operator describes them as unrelated.",
    "Source independence: SHARED ROOT. Both incidents are documented primarily by the same operator. Independent outlets reported the operator's accounts; they did not verify the incidents independently. The record also does not establish whether the Artifactory flaw used in the second incident is the flaw that gave egress in the first.",
    "The Position rates itself EMERGING on this base.",
    "Signals compiled from the CHQ Classification Log. Docket issued under CHQ-D-2026-PIG v1.0 (see CHQ-D-2026-GTR). Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-017 v1.0.",
    "Event independence: established. The two founding incidents are distinct events in distinct environments, with different escalation paths, and the operator describes them as unrelated.",
    "Source independence: SHARED ROOT. Both incidents are documented primarily by the same operator. Independent outlets reported the operator's accounts; they did not verify the incidents independently. The record also does not establish whether the Artifactory flaw used in the second incident is the flaw that gave egress in the first.",
    "The Position rates itself EMERGING on this base.",
    "Signals compiled from the CHQ Classification Log. Docket issued under CHQ-D-2026-PIG v1.0 (see CHQ-D-2026-GTR). Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "1561b2532d341f2e03edcc0397a4604d84af4211537681d49b52728077b8d883",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-028 Docket Hash",
      "scope": "the evidence record"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-017 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
