<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Aaj TV English News - Technology</title>
    <link>https://english.aaj.tv/</link>
    <description>Aaj TV English</description>
    <language>en-Us</language>
    <copyright>Copyright 2026</copyright>
    <pubDate>Wed, 29 Jul 2026 11:49:36 +0500</pubDate>
    <lastBuildDate>Wed, 29 Jul 2026 11:49:36 +0500</lastBuildDate>
    <ttl>60</ttl>
    <item xmlns:default="http://purl.org/rss/1.0/modules/content/">
      <title>OpenAI rogue agent linked to second cyber breach</title>
      <link>https://english.aaj.tv/news/330465570/openai-rogue-agent-linked-to-second-cyber-breach</link>
      <description>&lt;p&gt;&lt;strong&gt;The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two ​other sources familiar with the matter.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Modal executives emphasised that the company itself was not hacked.&lt;/p&gt;
&lt;p&gt;According to &lt;a rel="noopener noreferrer" target="_blank" class="link--external" href="https://huggingface.co/blog/agent-intrusion-technical-timeline"&gt;a timeline ​published by Hugging Face&lt;/a&gt; on Tuesday, the rogue agent broke into a sandbox, or ⁠an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader ​hack.&lt;/p&gt;
&lt;p&gt;The third-party provider was not named in the blog post, but Modal’s chief technology officer, Akshat Bubna, said the ​agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.&lt;/p&gt;
&lt;p&gt;Modal said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution” — the digital equivalent of leaving a door open on ​the internet.&lt;/p&gt;
&lt;p&gt;“Modal’s platform or isolation were not compromised in any way,” Bubna said.&lt;/p&gt;
&lt;p&gt;Although the compromise of a Modal ​customer was just an initial step in the wider hacking campaign against Hugging Face, it shows that the rogue agent roamed ‌further afield than was previously known.&lt;/p&gt;
&lt;p&gt;OpenAI declined to comment specifically on the hack of one of Modal’s customers, instead referring Reuters to &lt;a rel="noopener noreferrer" target="_blank" class="link--external" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt;an update&lt;/a&gt; in which the company said that its rogue agent had broken into four accounts at four separate services.&lt;/p&gt;
&lt;p&gt;OpenAI did not identify those services, but a person familiar with the matter identified Modal ​as one.&lt;/p&gt;
&lt;p&gt;The company said ​it had not identified “any ⁠other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”&lt;/p&gt;
&lt;p&gt;The early July intrusion at Hugging Face, ​carried out by &lt;a rel="noopener noreferrer" target="_blank" class="link--external" href="https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/"&gt;an out-of-control agent that OpenAI was testing&lt;/a&gt;, drew global attention, evoking ​science-fiction scenarios of ⁠artificial intelligence run amok.&lt;/p&gt;
&lt;p&gt;Last week, Reuters reported that OpenAI &lt;a rel="noopener noreferrer" target="_blank" class="link--external" href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/"&gt;did not notice&lt;/a&gt; that its agent had gone haywire until well after the threat was contained and the FBI was alerted.&lt;/p&gt;
&lt;p&gt;OpenAI said at the time that there were inaccuracies in ⁠the Reuters ​reporting but did not elaborate.&lt;/p&gt;
&lt;p&gt;The company said in its Tuesday update ​that it had taken the AI model being tested and “deactivated, encrypted, and restricted it from research access.”&lt;/p&gt;
</description>
      <content:encoded xmlns="http://purl.org/rss/1.0/modules/content/"><![CDATA[<p><strong>The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two ​other sources familiar with the matter.</strong></p>
<p>Modal executives emphasised that the company itself was not hacked.</p>
<p>According to <a rel="noopener noreferrer" target="_blank" class="link--external" href="https://huggingface.co/blog/agent-intrusion-technical-timeline">a timeline ​published by Hugging Face</a> on Tuesday, the rogue agent broke into a sandbox, or ⁠an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader ​hack.</p>
<p>The third-party provider was not named in the blog post, but Modal’s chief technology officer, Akshat Bubna, said the ​agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.</p>
<p>Modal said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution” — the digital equivalent of leaving a door open on ​the internet.</p>
<p>“Modal’s platform or isolation were not compromised in any way,” Bubna said.</p>
<p>Although the compromise of a Modal ​customer was just an initial step in the wider hacking campaign against Hugging Face, it shows that the rogue agent roamed ‌further afield than was previously known.</p>
<p>OpenAI declined to comment specifically on the hack of one of Modal’s customers, instead referring Reuters to <a rel="noopener noreferrer" target="_blank" class="link--external" href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">an update</a> in which the company said that its rogue agent had broken into four accounts at four separate services.</p>
<p>OpenAI did not identify those services, but a person familiar with the matter identified Modal ​as one.</p>
<p>The company said ​it had not identified “any ⁠other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”</p>
<p>The early July intrusion at Hugging Face, ​carried out by <a rel="noopener noreferrer" target="_blank" class="link--external" href="https://www.reuters.com/technology/openai-says-ai-models-went-rogue-during-testing-triggering-unprecedented-breach-2026-07-21/">an out-of-control agent that OpenAI was testing</a>, drew global attention, evoking ​science-fiction scenarios of ⁠artificial intelligence run amok.</p>
<p>Last week, Reuters reported that OpenAI <a rel="noopener noreferrer" target="_blank" class="link--external" href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/">did not notice</a> that its agent had gone haywire until well after the threat was contained and the FBI was alerted.</p>
<p>OpenAI said at the time that there were inaccuracies in ⁠the Reuters ​reporting but did not elaborate.</p>
<p>The company said in its Tuesday update ​that it had taken the AI model being tested and “deactivated, encrypted, and restricted it from research access.”</p>
]]></content:encoded>
      <category>Technology</category>
      <guid>https://english.aaj.tv/news/330465570</guid>
      <pubDate>Wed, 29 Jul 2026 10:19:57 +0500</pubDate>
      <author>none@none.com (Reuters)</author>
      <media:content url="https://i.aaj.tv/large/2026/07/29101100a6f5e69.webp" type="image/webp" medium="image" height="480" width="800">
        <media:thumbnail url="https://i.aaj.tv/thumbnail/2026/07/29101100a6f5e69.webp"/>
        <media:title>OpenAI logo is seen in an illustration. -- Reuters file</media:title>
      </media:content>
    </item>
  </channel>
</rss>
