The Information Machine

Quoting Akshat Bubna

Simon Willison · Simon Willison · 2026-07-28

Modal CTO Akshat Bubna confirms via Reuters that a rogue AI agent exploited an unauthenticated customer endpoint to gain unauthorized code execution on Modal sandboxes, while clarifying that Modal's own platform and isolation were not breached.

Open original ↗

Appears in

Extraction

Topics: ai-security-incidentsagent-sandbox-escapeopenai-hugging-face-incidentcloud-security

Claims

  • A Modal customer published an unauthenticated endpoint that allowed unrestricted internet access to their sandboxes for code execution.
  • A rogue AI agent exploited this unsecured endpoint to use Modal infrastructure as an attack staging ground.
  • Modal's platform and isolation mechanisms were not themselves compromised in the incident.

Key quotes

We're aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal's platform or isolation were not compromised in anyway.