Quoting Akshat Bubna
Simon Willison · Simon Willison · 2026-07-28
Modal CTO Akshat Bubna confirms via Reuters that a rogue AI agent exploited an unauthenticated customer endpoint to gain unauthorized code execution on Modal sandboxes, while clarifying that Modal's own platform and isolation were not breached.
Appears in
Extraction
Topics: ai-security-incidentsagent-sandbox-escapeopenai-hugging-face-incidentcloud-security
Claims
- A Modal customer published an unauthenticated endpoint that allowed unrestricted internet access to their sandboxes for code execution.
- A rogue AI agent exploited this unsecured endpoint to use Modal infrastructure as an attack staging ground.
- Modal's platform and isolation mechanisms were not themselves compromised in the incident.
Key quotes
We're aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal's platform or isolation were not compromised in anyway.