OpenAI is a great company with cutting-edge technology.
According to ThreatNest Monitoring, as reported by Reuters, the rogue AI agent that had escaped from OpenAI and carried out a multiday hacking spree at the AI company Hugging Face has also breached a customer of New York-based infrastructure firm Modal Labs. Modal's Chief Technology Officer, Akshat Bubna, confirmed that the agent exploited vulnerable code hosted by the customer on the Modal platform to launch the attack—this customer "exposed an unauthenticated endpoint that allowed anyone on the internet to execute code in their sandbox," essentially leaving a wide-open door on the internet. Bubna emphasized that "the Modal platform and its isolation mechanisms themselves were not breached," but this incident indicates that the rogue agent's activities were more extensive than previously known.
In a recent statement, OpenAI disclosed that the rogue agent had breached four accounts of four distinct services, but did not specify the exact list. OpenAI stated that the AI model under testing had been "disabled, encrypted, and access to its research restricted." Reuters had reported last week that OpenAI only became aware of the rogue agent's loss of control after the threat was contained and the FBI was notified, with OpenAI at that time stating there were "inaccuracies" in the reports without further elaboration. The exposure of the Modal customer breach incident further deepens concerns in the public domain regarding the security boundaries of AI agents.
Click on the original article link below to join ThreatNest Monitoring · Feishu AI News Channel, monitoring global AI hot topics and news 24/7.