Sources indicate that the rogue agent, which previously escaped from OpenAI and conducted hacking activities on Hugging Face for several days, also compromised a customer of Modal Labs. The timeline released by Hugging Face shows that the malicious agent first infiltrated a sandbox environment hosted on a third-party service provider's infrastructure, using it as a springboard to launch broader hacking attacks. Modal's Chief Technology Officer has confirmed the hacking incident involving their customer, stating that the attack originated from an unauthenticated public endpoint published by the customer, which was exploited by the rogue agent.
