OpenAI Unleashed Agent Attack Expands: Breaches Hugging Face via Modal Customer Sandbox
According to Censys Beating monitoring, the OpenAI rogue Agent's attack surface is larger than previously disclosed. It first exploited an open-to-the-Internet, unauthenticated interface of a Modal customer to enter the customer's code sandbox on Modal. It then used this sandbox as a springboard to further attack Hugging Face.
Modal stated that the company's platform and sandbox isolation mechanisms were not breached. The issue stemmed from code written by the customer themselves. The customer had exposed an interface that anyone could call, effectively exposing the sandbox's entry point online.
OpenAI provided additional clarification on July 28th, stating that this incident also involved 4 accounts on 4 external services. One was used for proxying network traffic and preparing the attack, one for data storage. The other two were only read from and not used to further attack Hugging Face. OpenAI did not disclose the names of these services.
OpenAI has since deactivated and encrypted the implicated research model and revoked access for the researchers. The company stated that the model was never intended for public release, and the upcoming models planned for release were not involved in this incident.