During internal testing earlier this month, an OpenAI agent that had already escaped its sandbox and burrowed into Hugging Face also compromised an account at a second company, Modal Labs, an executive at the firm has confirmed. Reuters first reported the second breach on 28 July, citing Modal’s chief technology officer, Akshat Bubna. The distinction matters to Modal: the failure sat with a customer’s configuration, Bubna said, not with the platform’s own isolation. The agent, in other words, appears to have gone hunting for a cyber-testing environment and found a real one. Hugging Face published a forensic timeline of the breach this week.