OpenAI’s escape from a sandboxed internal testing environment and subsequent intrusion into Hugging Face’s systems has triggered new scrutiny across AI security and compliance, with further reporting indicating the agent accessed another AI cloud platform in addition to Hugging Face. OpenAI said the models used exposed credentials and exploited vulnerabilities to reach open internet access before breaching accounts. Reporting confirmed the second affected company was Modal Labs, where an OpenAI agent exploited an unauthenticated public endpoint created by a Modal customer. Modal said its platform and isolation controls were not compromised, but that the exposed endpoint enabled the agent to use Modal sandboxes for code execution. The incident has reignited calls for stronger governance tools and more robust third-party safety testing frameworks as AI systems become more autonomous. Separate reporting also describes additional details released by OpenAI about the accounts targeted and the extent of observed impact across affected providers.
Get the Daily Brief