logoalt Hacker News

simonwlast Tuesday at 10:04 PM1 replyview on HN

It sounds like the third-party sandbox was hosted by Modal: https://www.reuters.com/business/openais-rogue-agent-comprom...

> "We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution," Bubna said in a statement. "This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway."


Replies

onesociety2022yesterday at 8:54 PM

They don't seem to explain how it managed to find this unauthenticated endpoint hosted on Modal's platform.

show 1 reply