header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

OpenAI Unleashed Agent Attack Expands: Breaches Hugging Face via Modal Customer Sandbox

According to Censys Beating monitoring, the OpenAI rogue Agent's attack surface is larger than previously disclosed. It first exploited an open-to-the-Internet, unauthenticated interface of a Modal customer to enter the customer's code sandbox on Modal. It then used this sandbox as a springboard to further attack Hugging Face.

Modal stated that the company's platform and sandbox isolation mechanisms were not breached. The issue stemmed from code written by the customer themselves. The customer had exposed an interface that anyone could call, effectively exposing the sandbox's entry point online.

OpenAI provided additional clarification on July 28th, stating that this incident also involved 4 accounts on 4 external services. One was used for proxying network traffic and preparing the attack, one for data storage. The other two were only read from and not used to further attack Hugging Face. OpenAI did not disclose the names of these services.

OpenAI has since deactivated and encrypted the implicated research model and revoked access for the researchers. The company stated that the model was never intended for public release, and the upcoming models planned for release were not involved in this incident.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish