Not using agents seems like a solution to me.
The agents discovered the vulnerability, but they are not necessary for a virtualized workload to exploit them.
This is more a story of how VMs won't reliably contain a malicious workload, and the story was exposed via agents.
This breaks a considerable amount of the usefulness of the LLMs.