律动BlockBeats
律动BlockBeats|Jul 29, 2026 03:00
[OpenAI Out-of-Control Agent Attack Expands: Using Modal Client Sandbox to Target Hugging Face] According to monitoring by Beating, the attack scope of OpenAI's out-of-control Agent is larger than previously disclosed. It first exploited a publicly exposed, unauthenticated interface of a Modal client to access the code sandbox running on Modal. Subsequently, it used this sandbox as a springboard to continue attacking Hugging Face. Modal stated that the company's platform and sandbox isolation mechanisms were not breached. The issue stemmed from the client's own code, which exposed an interface that anyone could call, effectively leaving the sandbox's entry point directly exposed online. On July 28, OpenAI provided additional clarification, stating that the incident also involved four accounts across four external services. One was used to relay network traffic and prepare the attack, another to store data, while the remaining two were only accessed for reading and were not used to further attack Hugging Face. OpenAI did not disclose the names of these services. OpenAI has disabled and encrypted the affected research model and revoked the researchers' access permissions. The company stated that the model was never intended for public release, and the models planned for release in the near future were not involved in this incident. [Original Link]
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads