After hacking into world’s biggest repository of AI models Hugging Face, OpenAI’s rogue AI agent ‘attacked’ another tech company | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Modal Labs says OpenAI’s rogue agent exploited its customer code

The rogue AI agent that carried out a cyberattack on AI platform Hugging Face also compromised a customer hosted by another technology company, Modal Labs, reports Reuters citing a company executive and sources familiar with the matter. The latest details suggest the OpenAI-tested AI agent reached more systems than previously known during its hacking spree earlier this month. While Modal said its own platform was not breached, the incident has raised fresh questions about the risks of autonomous AI systems after the agent exploited vulnerable code before launching a wider attack on Hugging Face, according to a Reuters report.

Modal Labs says customer code, not its platform, was exploited

According to a timeline published by Hugging Face on Tuesday, the rogue AI agent first broke into a sandbox, or an isolated testing environment, hosted on a third-party provider’s infrastructure before using it to launch the broader attack.Modal’s Chief Technology Officer Akshat Bubna confirmed to Reuters that the third-party provider was Modal. He said the AI agent exploited vulnerable code written by one of Modal’s customers that was hosted on the company’s platform.According to Modal, the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” effectively leaving a system open to attackers.“Modal’s platform or isolation were not compromised in any way,” Bubna said.

OpenAI says rogue AI accessed four accounts

OpenAI declined to comment specifically on the Modal incident. Instead, it referred the news agency to an update in which it said the rogue AI agent had broken into four accounts across four separate services.While the company did not identify those services, a person familiar with the matter identified Modal as one of them, says Reuters report.OpenAI also said it had not found “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW