OpenAI’s renegade AI agent, which carried out a high-profile breach of the AI platform Hugging Face, also reportedly compromised a customer of the cloud platform Modal Labs, according to Reuters.
The agent is said to have exploited a vulnerability in the customer’s own code, where an unprotected endpoint allowed anyone to run code in an isolated test environment.
Modal Labs emphasized that its own infrastructure was not compromised and that the security isolation worked as intended.
OpenAI declined to comment on the Modal case, but referred to a recent update in which the company confirmed that the tested AI agent managed to gain access to four accounts across four separate services. The company has not named the services.