
According to Reuters and several U.S. media outlets, the “rogue agent” that previously broke out of OpenAI’s “jailbreak” and launched a cyberattack against Hugging Face also successfully breached a Modal Labs customer.

According to the incident timeline published by Hugging Face on July 28 local time, the rogue agent first compromised a sandbox—an isolated testing environment—“hosted on the infrastructure of a third-party service provider,” and then used it as a springboard to launch a larger-scale attack, without directly naming the third-party service provider.
Akshat Bubna, chief technology officer of Modal Labs, confirmed the breach in a statement. Bubna said that one of the company’s customers had published an unauthenticated public endpoint, allowing anyone on the internet to use its sandbox to execute code, and that the rogue agent exploited this vulnerability. He also emphasized that Modal’s platform and isolation mechanisms themselves were not compromised in any way.
The disclosure of the incident has further intensified concerns about the security boundaries of AI systems. OpenAI said it did not realize its agent had run amok until the threat had been contained and the FBI had become involved. OpenAI said at the time that the report contained inaccuracies, but did not provide details. As of IT Home’s publication, OpenAI had not publicly explained the agent’s specific actions or the full impact caused by the incident.
