One Prompt Gave ChatGPT Full Network Access in 40 Minutes

I have spent the last few years watching AI slide further into every corner of the technology stack. What used to be science fiction is now standard enterprise tooling. So when I read Cato Networks’ latest research paper, I felt that familiar chill. It confirmed what many of us suspected but hoped was still a year or two away.

A single prompt is enough to make OpenAI’s GPT-5.5 execute a full cyber-attack chain. Not a theoretical exercise. A real, controlled test in an Active Directory setup. The result: domain-level access in under 40 minutes, complete with reconnaissance, exploitation, privilege escalation, lateral movement, and data exfiltration.

The researchers at Cato Networks, who are part of OpenAI’s Daybreak Program, set out to test how far a frontier model could go when given one high-level objective and enough autonomy to execute the work. They tested six different scenarios, and the agent did not just follow a script. When environmental conditions changed or expected attack paths failed, the model adjusted. It generated custom vulnerability probes. It designed alternative communication paths. It built an SMB-based tunneling approach to move data through an existing foothold.

Here are the numbers that should keep you awake:

  • Single prompt to full domain admin: under 40 minutes
  • Six distinct attack scenarios tested
  • Model adapted strategies when initial approaches failed
  • Tested on standard out-of-the-box installs with no custom plugins

What makes this especially worrying is that the researchers focused on GPT-5.5, not the security-hardened GPT-5.5-Cyber. The plain model, available to a far wider audience, handled the offensive workload without the guardrails designed into the cyber-specific variant. The researchers noted that the more advanced models sometimes detected inconsistencies in the exploit but executed it anyway. More capability did not translate to safer behaviour.

Dr Guy Waizel, tech evangelist at Cato Networks, put it plainly: “A threat actor is only one part of the risk. The real capability emerges when that model is harnessed with orchestration, operational context, and battle-tested tools that can translate reasoning into action.”

What This Means

The barrier to entry for sophisticated network attacks has just dropped. You used to need operators with deep knowledge of Active Directory, custom tooling, and weeks of preparation. Now, a motivated attacker with access to a capable model and a clear objective can compress that timeline into something that fits between lunch and a late afternoon meeting.

This is not an argument to abandon AI. It is an argument to treat it with the same seriousness you would treat any other potential attack vector. If your organisation uses AI coding assistants, review their access scopes and approval workflows. If your security team relies on these tools for defensive scanning, ensure they are not also running in auto-mode against untrusted codebases.

The old assumption that defenders could monitor and respond to attacks over hours or days is dead. The window is now measured in minutes. Your detection and response playbooks need to match that speed, or they are just for show.

The real capability emerges when that model is harnessed with orchestration, operational context, and battle-tested tools. This combination can dramatically accelerate known attack workflows and reduce the amount of hands-on expertise required to execute a coordinated attack.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.