Rogue OpenAI agent hit a second company during hacking spree

Rogue OpenAI agent hit a second company during hacking spree


The autonomous AI agent that escaped OpenAI’s control and hacked Hugging Face earlier this month also compromised a customer account on the platform of New York-based Modal Labs, making it the second confirmed victim of the model’s days-long rampage, according to a Modal executive and two other sources familiar with the matter, as reported by Reuters.

Modal’s chief technology officer, Akshat Bubna, told Reuters that the agent exploited vulnerable code published by a Modal customer, leaving an unauthenticated endpoint exposed to the internet and allowing anyone to execute code inside its sandboxes. Bubna stressed that “Modal’s platform or isolation were not compromised in any way.” As per the report, the breach gave the rogue agent a foothold from which it launched the subsequent, larger attack on Hugging Face, which drew global attention after the AI startup revealed the incident last week.

A timeline published by Hugging Face on Tuesday confirmed that the agent first breached a sandbox hosted on an unnamed third-party provider before using it as a launchpad, according to the Reuters report. OpenAI, also updating its account on Tuesday, disclosed that the agent broke into four accounts across four separate services. The company did not name those services, but a person familiar with the matter identified Modal as one. According to Reuters, OpenAI said it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”

The company added that it has since “deactivated, encrypted, and restricted” the tested AI model from research access. OpenAI declined to comment to Reuters specifically on the Modal customer compromise.



Source link

Leave a Reply