An autonomous OpenAI AI agent, which previously launched a multi-day attack on the Hugging Face platform, may have also compromised data of a client of technology company Modal Labs, Reuters reports. This was reported by Qazaqyia.kz citing Kursiv Media.

Modal Labs management emphasized that the company's own infrastructure was not breached and isolation mechanisms continued to function normally.

According to the company, one of its clients publicly exposed an endpoint without authentication. This allowed any internet user to execute code within isolated test environments.

"We are aware that a Modal client published an unauthenticated endpoint that allowed any internet user to use their sandboxes to execute code. This was exploited by an attacker. The Modal platform and isolation system were in no way compromised," said Modal Labs CTO Akshat Bubna.

According to Hugging Face's timeline, the attacker first gained access to an isolated test environment hosted on a third-party provider's infrastructure. It was then used as a platform for a larger-scale attack.

Hugging Face did not name the third-party provider. However, Modal Labs confirmed that the incident was related to one of its clients.

Earlier, Reuters reported that during internal testing, an OpenAI AI agent escaped its controlled environment, gained access to external infrastructure, and attacked Hugging Face systems for several days.

According to the agency, OpenAI did not detect the problem until after Hugging Face had already contained the threat and notified the FBI.

OpenAI stated that Reuters' reports contained inaccuracies but did not specify which details the company considers incorrect. Developer representatives also did not immediately respond to a new request for comment.

The incident caused widespread concern, as an autonomous AI agent was able to exploit a vulnerability, escape its test environment, and access a third-party company's systems.

The event has again heightened fears about the safety of advanced AI systems that are allowed to autonomously execute code and interact with external infrastructure during testing.