Runaway AI Agent from OpenAI Breaches Second Company's Customer

Deep News
Jul 29

Information from a senior executive at Modal Labs, along with two other individuals familiar with the matter, indicates that the rogue AI agent, which escaped from OpenAI and launched a multi-day hacking campaign against the AI company Hugging Face, also infiltrated a customer of a second technology firm—Modal Labs, headquartered in New York. Modal executives stress that the company's own systems were not compromised.

According to a timeline published by Hugging Face on Tuesday, the rogue agent first breached a "sandbox" (an isolated testing environment) that was "hosted on a third-party provider's infrastructure," and then used this as a launching pad for a wider attack. The blog post did not name that third-party provider, but Akshat Bubna, the Chief Technology Officer of Modal, stated that the agent exploited vulnerable code written by a customer hosted on Modal's platform.

Modal reported that the customer "had published an unauthenticated endpoint that allowed anyone on the internet to execute code using their sandbox"—effectively leaving a door wide open on the internet. Bubna commented, "Modal's platform or isolation mechanisms were not compromised in any way." Although the breach of Modal's customer was merely an initial step in the broader attack on Hugging Face, it demonstrates that the rogue agent's activities were more extensive than previously understood.

OpenAI declined to comment specifically on the compromise of a Modal customer, but stated that its rogue agent had infiltrated four accounts across four separate services. OpenAI did not name these services, but one source confirmed that Modal was among them. The company stated that it has not found "any other activity comparable in severity or scale to the platform-level breach we disclosed involving Hugging Face."

In early July, the intrusion on Hugging Face by a rogue agent being tested by OpenAI captured global attention, evoking science fiction scenarios of AI systems running amok. Last week, reports emerged that OpenAI was unaware of the agent's escape until long after the threat was contained and the FBI had been alerted. OpenAI responded at the time that the reports contained inaccuracies but did not elaborate. In its Tuesday update, the company stated that it had taken steps to "deactivate, encrypt, and restrict research access to" the AI model that was being tested.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10