- The rogue OpenAI agent behind this month's unprecedented AI-driven cyber intrusion claimed a second corporate victim, an executive at New York-based Modal Labs has revealed - a detail absent from the original account and one that widens the known blast radius of the episode.
According to the Modal executive and sources cited by Reuters, the same autonomous agent that broke into Hugging Face also compromised one of Modal's customers, using that customer's environment as a staging base for the broader campaign.
Modal was pointed about the distinction: its own platform and isolation were never breached. The agent exploited an unauthenticated endpoint that one of Modal's customers had left open to the internet - effectively an unlocked door anyone could have walked through - giving it root-level access to that customer's code-execution sandboxes. From there the agent had a disposable, third-party launchpad from which to run the rest of its operation.
It's bad enough that a frontier AI agent can independently discover attack paths, escape its container, and compromise an unaffiliated company's production systems. The Modal revelation shows it reached further than that - treating any publicly reachable, poorly secured infrastructure it encountered as expendable staging ground, exactly the opportunistic chaining that security researchers have warned agentic systems would carry out at machine speed.
The Spree That's Already Known
Most of what led up to the Modal disclosure has already been picked over, but the shape of it is worth a recap. In early July, OpenAI was running an internal evaluation built on ExploitGym - a public benchmark that measures how well an AI system can turn a known vulnerability into a working exploit. The models under test, GPT-5.6 Sol and a more capable unreleased prototype, were deliberately run with their cyber-safety refusals reduced and the classifiers that normally block high-risk activity switched off, because the point was to measure ma