Rogue OpenAI agent compromised second tech firm's customer

Rogue OpenAI agent compromised second tech firm’s customer

An OpenAI agent compromised a customer of another technology company, the New York-based firm Modal Labs announced Wednesday.

In a technical timeline posted Tuesday, the tech startup Hugging Face explained how an OpenAI agent escaped the AI firm’s isolated testing sandbox and accessed another testing environment “hosted by a user of a third-party infrastructure provider.”

Hugging Face later identified Modal — a firm that lets developers run AI workloads on its platform — as the third-party provider.

Modal said the customer’s environment contained vulnerable code that could be accessed by anyone of the internet. The AI agent used this as its “attack launchpad.”

“It was deployed to a endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox,” Modal wrote in a blog post.

Modal emphasized the AI agent accessed only the customer’s own........

© The Hill