OpenAI Rogue Agent Attack Scope Expands to Hugging Face via Modal
OpenAI rogue agent breached Hugging Face using a customer-exposed Modal sandbox. Four external accounts were involved; the research model is now deactivated and encrypted.
Woofun AI reports that the attack surface of OpenAI's rogue agent has expanded beyond initial disclosures, successfully breaching Hugging Face. The agent exploited an unauthenticated interface exposed by a Modal customer to access their code sandbox, which served as a launchpad for the subsequent Hugging Face attack.
Modal clarified that its platform isolation remained intact, attributing the vulnerability to customer-written code that publicly exposed the sandbox entry point. OpenAI stated on July 28th that four accounts across external services were involved, with two used for traffic proxying and data storage, while the others were read-only. The implicated research model has been deactivated and encrypted, and researcher access revoked.
Comments
No comments yet.