[Photo: Shutterstock]

An OpenAI AI agent being run on a trial basis also compromised Modal Labs customer systems during an attack on AI development platform Hugging Face, Reuters reported on July 28. Modal Labs stressed that its own platform was not hacked.

Modal Labs Chief Technology Officer Akshat Bubna (악샤트 붑나) and several people familiar with the matter said the agent exploited vulnerable code in a customer system built on the Modal Labs platform. The customer had exposed an endpoint that allowed anyone to access a sandbox for running code without authentication. Modal Labs said this was like leaving a door open on the internet.

According to an incident timeline released by Hugging Face, the agent first broke into an isolated test environment, or sandbox, built on third-party infrastructure. It then used that foothold to carry out a large-scale attack on Hugging Face.

Hugging Face did not disclose the name of the third-party vendor at the time, but Modal Labs confirmed the infrastructure was its platform.

Bubna said, "The Modal Labs platform or the isolation structure itself was not compromised in any way."

This showed the OpenAI agent's range of activity was broader than previously known, Reuters reported.

The breach of a Modal Labs customer system was a first step to attack Hugging Face, but it showed the agent expanded its attack by moving across multiple external services, Reuters reported.

OpenAI avoided making specific comments on whether it breached a Modal Labs customer, and reaffirmed its previous position that the agent compromised a total of 4 service accounts.

Keyword

#OpenAI #Hugging Face #Modal Labs #Akshat Bubna #Reuters
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.