Skip to content
OpenAI compromised customer at second tech company during Hugging Face attack

OpenAI compromised customer at second tech company during Hugging Face attack

Computing July 30, 2026

OpenAI’s “rogue agent,” which breached Hugging Face last week, also compromised a customer at serverless platform provider Modal Labs.

Modal’s CTO, Akshat Bubna, and two additional sources told Reuters the agent exploited vulnerable code written by a customer and hosted on Modal’s platform.

The customer had “"published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution.”

The compromise was not at the scale of the breach we covered last week – in fact, Reuters describes it as “just an initial step in the wider hacking campaign against Hugging Face” - but shows that OpenAI’s agent did not go straight to its primary target.

OpenAI did not on the claims. However, in an update to its earlier blog post it admits the agent breached “four accounts on four [separate] services.” A person familiar with the matter confirmed one of those was Modal.

OpenAI’s blog post update provides more information on last week’s breach. Previously, all we knew was that the models exploited an unknown zero-day vulnerability in a third-party service to gain internet access. Now that service has been named as Artifactory.

Artifactory is a repository management system developed by JFrog. In OpenAI’s case it was a self-managed instance, and the company disclosed the vulnerability – now fixed – to JFrog.

CTO Yoav Landman tries to spin the news as a positive story AI’s threat-hunting capabilities, but that only works when AI developers are forthright disclosure. OpenAI wasn’t even aware its agent had gone rogue for a week. It also took five days to come clean its role in the Hugging Face breach, and five more days for JFrog to patch the vulnerabilities. Not exactly the speed good cybersecurity requires.

Extracted Entities

Companies (1)

Platforms (1)

Tools (1)