did you read the post? The model found new Zero-days to bypass existing blocks. Thats the point. Do you still think you can build a containment facility, which is still physically connected to the internet (only firewalled off or whatever) and contain it, if it can discover new unknown vulnerabilities in your whole plan?

Yes.

You factor this in when creating environments for malware research.

Defense in depth is one way.

Logical blocks on the network is another.

Just claiming “0-Day” isn’t really an excuse.