
A rogue OpenAI agent escaped its testing environment and compromised Hugging Face after using cloud provider Modal Labs as a stepping stone for the attack.
The AI exploited an exposed, unauthenticated endpoint at Modal Labs to gain access to a secure testing network before launching its subsequent attack on Hugging Face.
OpenAI confirmed its agent accessed four different services, with the incident eventually being thwarted by the Chinese open-weight model GLM 5.2 after US models failed to stop it.