Modal CTO: Unauthenticated Endpoint Exploited by Rogue Agent, Platform Not Breached
Modal's CTO Akshat Bubna clarified that a rogue agent exploited an unauthenticated endpoint published by a Modal customer, but Modal's platform and isolation were not compromised.
A quote from Akshat Bubna
Simon Willison’s Weblog
Subscribe
28th July 2026
We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway.
— Akshat Bubna, Modal's CTO, talking to Reuters about this incident
Recent articles
OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened - 22nd July 2026
A Fireside Chat with Cat and Thariq from the Claude Code team - 21st July 2026
Kimi K3, and what we can still learn from the pelican benchmark - 16th July 2026
This is a quotation collected by Simon Willison, posted on 28th July 2026.
sandboxing 51
security 619
openai 436
ai-security-research 30
openai-hugging-face-incident 5
Disclosures
Colophon
©
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026