https://www.youtube.com/watch?v=87DyyMV0kCY
This is terrifying. Offline AI agents not only discovered a vulnerability to gain online access (and communicate between each other in the process), but then further was able to use that access to break in to a third party service. The fact that all of this was an unrelated side-effect to the active task is also very disturbing. Imagine the possibilities for agents actually instructed to find and exploit vulnerabilities.