惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 叶小钗
月光博客
月光博客
Last Week in AI
Last Week in AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
IT之家
IT之家
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
博客园 - 司徒正美
爱范儿
爱范儿

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
OpenAI agents breach Modal client system after Hugging Fa...
Suhasini Srinivasaragavan · 2026-07-29 · via Enterprise – Silicon Republic

OpenAI’s ‘rogue’ agents took advantage of a code vulnerability, experts explained.

US cloud company Modal has confirmed that OpenAI’s agents were able to hack into one of its customer’s systems when the AI models breached containment and gained unauthorised access to Hugging Face earlier this month.

Last week’s incident sent shockwaves across the tech industry, raising serious concerns around AI’s rapidly advancing ability to bypass boundaries and, effectively, go ‘rogue’.

It comes amid increased scrutiny around OpenAI and Anthropic’s new AI models, resulting in gated launches and greater government involvement. Both AI giants have ramped up efforts to go public in blockbuster listings as they compete to gain market dominance and enterprise footing.

OpenAI CEO Sam Altman, in a recent interview, said that the Hugging Face breach was the first security incident he felt “very viscerally”.

“I feel a little surprised that more people don’t feel it so viscerally,” he told Invest Like The Beast in a podcast episode published on Tuesday (28 July).

Hugging Face said that OpenAI’s agents accessed a sandbox hosted on a ​third-party provider’s infrastructure when it breached containment last week. A sandbox is an isolated environment where AI models are tested without production classifiers, or guardrails.

Modal chief technology officer Akshat Bubna confirmed that its customer set up a publicly accessible interface which enabled anyone to use their sandbox.

“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Bubna told Axios. “Their code had a vulnerability that was exploited … This was used by the rogue agent. Modal’s platform was not compromised in any way.”

In an updated statement, OpenAI said that none of its upcoming models were involved in exploiting Hugging Face. It explained that its testing models were able to identify and exploit an unknown zero-day vulnerability to gain access to the internet, which enabled them to access Hugging Face.

“In our ongoing review of the Hugging Face intrusion and broader activity from our models, we have been finding a small number of cases where the models identified and used publicly exposed credentials at the account level on other publicly-available services,” the company said.

“Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face”.

Cybersecurity experts, however, believe that the breach is a result of “missing governance and control”.

“When conducting security testing you should define what is in and out of the testing scope, even for broad red team engagements,” said Richard Davies, director of cyber solutions at Talion.

“The reported impacts and timelines indicate this was not in place.”

CybaVerse chief technology officer Simon Phillips said: “The model, tooling and instructions were very loose, almost to the point it was told it could do anything on any system, which it clearly did.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.