Modal 回应 Hugging Face 智能体入侵事件:平台未被攻破
A note on the Hugging Face agent incident
Hugging Face 公布近期智能体入侵的技术时间线,其中将 Modal 列为智能体利用的第三方基础设施。Modal 回应称其平台与隔离机制未被攻破,攻击者获得的代码执行发生在客户自己部署的无鉴权公开端点容器内,处于 Modal 标准沙箱隔离边界中,其他客户工作负载未受影响。Modal 建议公网暴露的服务启用身份验证、IP 白名单、限制出站网络,并将用户提交的代码视为不可信。
当事方 Modal 直接说明平台未被攻破、攻击发生在客户容器的沙箱边界内,并给出公网暴露负载的防护建议。
Hugging Face published a technical timeline of a recent agent intrusion, which names Modal as the third-party infrastructure the agent used as a launchpad.
Modal's platform and isolation were not compromised in any way.
The environment involved was a customer's own application. It was deployed to a endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox. The code execution the attacker obtained took place inside that customer's own container, within Modal's standard sandbox isolation boundary. No other customer workloads were affected.
While customers can expose Sandboxes to unauthenticated traffic, this is never the default, and Modal provides the authentication, network, and monitoring controls to keep production workloads locked down. We recommend that anything exposed to the public internet require authentication, IP allowlist, restrict its outbound network access to only what it needs, and treat any code or input it accepts from users as untrusted.
For additional questions, email security@modal.com.
来源:Modal 官方工程博客(RSS) · modal.com