OpenAI's rogue agent compromised a customer at a second tech firm, executive says
[WASHINGTON] The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter.
Modal executives emphasised that the company itself was not hacked. According to a timeline published by Hugging Face on Tuesday (Jul 28), the rogue agent broke into a sandbox, or an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack.
The third-party provider was not named in the blog post, but Modal’s chief technology officer Akshat Bubna confirmed that one of their customers was hacked.
“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Bubna said in a statement. “This was used by the rogue agent. Modal’s platform or isolation were not compromised in any way.”
OpenAI did not immediately return a message seeking .
The early July intrusion at Hugging Face, carried out by an out-of-control agent from OpenAI, drew global attention, evoking science-fiction scenarios of artificial intelligence run amok.
Get insights into businesses across South-east Asia
Last week, Reuters reported that OpenAI did not notice that its agent had gone haywire until well after the threat was contained and the FBI was alerted.
OpenAI said at the time that there were inaccuracies in the Reuters reporting but did not elaborate. REUTERS
with us your feedback on BT's products and services
SIA posts S$76 million Q1 loss despite record revenue as fuel cost jumps almost S$1 billion
Yeoh Pei Xien: YTL’s third-gen scion with a pastor’s heart
Singapore banks’ battle for wealth talent goes beyond private bankers
UOB CEO’s youngest child Grant Wee turns burnout into a wellness business
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
