Agents
Quoting Akshat Bubna
We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform
We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway. — Akshat Bubna, Modal's CTO, talking to Reuters about this incident Tags: ai-security-research, openai, sandboxing, security, openai-hugging-face-incident
Related
- New from @Reuters: the OpenAI agent that hacked into Hugging Face also compromised code that a customer was running on @Modal. “We’re aware …
- Sources: the OpenAI agent that breached Hugging Face also compromised a customer at AI infrastructure company Modal Labs (Reuters)
- A note on the Hugging Face agent incident
- Why AI Infrastructure must evolve for Agent Experience — Akshat Bubna, Modal CTO
Source: Simon Willison | 2026-07-28