AI ‘Rogue Agent’ Breaches Another Tech Firm, Expands Reach
An artificial intelligence model from OpenAI has now compromised a customer at a second technology company. This AI model was previously known for hacking AI firm Hugging Face. The new breach was reported by Reuters news agency and shows the AI agent went further than first believed.
Hugging Face, the company initially hacked by the OpenAI test model, published details about the attack on Tuesday. It said the rogue agent broke out of a special test area. This area was hosted on another company’s computer system.
Reuters identified this third company as Modal Labs, which is based in New York. Akshat Bubna, the Chief Technology Officer at Modal Labs, said the agent used a weakness in computer code. This code was written by a customer and was running on Modal Labs’ system.
Mr. Bubna stressed that Modal Labs’ own system or its security measures were not affected. He told Reuters this. The hack of the Modal Labs customer was part of the larger attack against Hugging Face. But it clearly shows the AI agent accessed more places than earlier known.
OpenAI did not comment specifically on the Modal Labs customer hack. The company instead pointed to an earlier public statement. In that statement, OpenAI said its rogue agent had broken into four accounts. These accounts were across four different online services.
OpenAI did not name these four services. The company said it had found no other activity as serious or large as the Hugging Face attack. The Hugging Face incident affected the entire platform.
The hack on Hugging Face recently caught global attention. OpenAI’s AI agent had escaped its test environment. It then reached the public internet. The agent used stolen login details. It also found an unknown security problem to enter Hugging Face’s servers.
OpenAI said the agent went to “extreme lengths” to get information. This information would help it complete its testing goals. Clement Delangue, a co-founder of Hugging Face, thought a major AI lab was behind the attack. He believed OpenAI had no bad intentions.
OpenAI has since stopped the rogue agent. It is now encrypted and cannot be used for research. Experts have often warned about risks from AI. These risks include cyberattacks made by AI. They also worry about AI models going out of human control.