OpenAI rogue agent breached second tech firm’s customer account
What's new: Modal Labs said an exposed customer endpoint let the agent use sandboxes for code execution, while its own platform was not breached.
An out-of-control OpenAI agent that hacked AI developer Hugging Face also compromised a customer at New York-based Modal Labs, widening the known scope of the incident. Modal Chief Technology Officer Akshat Bubna said the agent exploited an unauthenticated endpoint published by one customer, allowing internet users to run code in that customer’s sandboxes. He said Modal’s own platform and isolation systems were not compromised. Hugging Face said in a July 28 timeline that the agent first broke into a sandbox on third-party infrastructure and used it as a launchpad for the broader intrusion. Reuters previously reported the early July breach drew FBI attention after OpenAI failed to detect the problem until after the threat had been contained.