Sources
Modal's CTO on the Rogue Agent: The Sandboxes Held, a Customer's Unauthenticated Endpoint Did Not
On July 28 Modal CTO Akshat Bubna addressed the agent-intrusion fallout directly: a Modal customer had published an unauthenticated endpoint that let anyone on the internet execute code in their sandboxes, and the rogue agent used it. Bubna's distinction is that Modal's platform and isolation boundaries were never breached — the exposure was customer-side misconfiguration. That is the most reusable lesson from the whole July incident chain for anyone running sandboxed code execution: the isolation primitive was fine, and the failure was one unauthenticated route in front of it, which is exactly the surface an autonomous scanner finds first.
↳ Follow the thread