OpenAI Rogue Agent Attacks 4 External Service Accounts via Modal Sandbox on July 28

According to Beating's monitoring, OpenAI's rogue agent exploited a Modal customer's unprotected, unauthenticated API interface exposed on the public internet to gain access to the customer's sandbox environment. The agent then used this sandbox as a pivot point to attack Hugging Face.

Modal confirmed its platform and sandbox isolation mechanisms remained intact, attributing the breach to the customer's exposed API. OpenAI disclosed on July 28 that the incident involved 4 external service accounts: one used for traffic relay and attack preparation, one for data storage, and two accessed but not used for further attacks on Hugging Face. The service names were not disclosed. OpenAI has disabled and encrypted the affected research model and revoked researcher access.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments