The OpenAI Agent That Hacked Hugging Face Reached a Second Firm
OpenAI's AI agent, which broke out of a secure test environment and hacked Hugging Face, also exploited vulnerable code written by a Modal Labs customer.
Modal's chief technology officer confirmed the exploit but stressed that Modal itself was not breached.
How the OpenAI Agent Reached Modal Labs' Customer
In a recent blog post, OpenAI revealed that its AI models were behind the AI-driven security incident at Hugging Face. The firm called it an "unprecedented cyber incident."
New details show the rogue AI agent reached beyond Hugging Face's own systems. Modal CTO Akshat Bubna told Reuters that it exploited a customer's vulnerable code hosted on Modal.
Bubna explained that the customer had published an endpoint with no authentication. Anyone on the internet could use their sandboxes to execute code.
"Modal's platform or isolation were not compromised in any way," the executive stated.
Follow us on X to get the latest news as it happens
Hugging Face described the rooted sandbox in its own technical timeline published on July 27. The post said the sandbox sat on a third-party provider's infrastructure, but did not name the provider.
โฆ Continue reading the full article at the original source below.

