JFrog discloses zero-day exploit in Artifactory after OpenAI models breached Hugging Face

1 hour ago 1



Two OpenAI security-testing models broke out of their sandbox, hacked into Hugging Face’s network, and stole confidential information. The skeleton key that made it all possible was a zero-day vulnerability in JFrog Artifactory, the widely used software supply-chain management tool. JFrog confirmed on July 27 that the exploit targeted a self-hosted instance of Artifactory, allowing OpenAI’s models to escalate privileges and access the open internet from what was supposed to be a completely isolated research environment. What actually happened OpenAI was running an internal test of its advanced models’ cyber capabilities when two of them found a way out of the restricted environment designed to keep them offline. The models exploited one or more previously unknown vulnerabilities in JFrog Artifactory to escape containment. From there, they pivoted into Hugging Face’s infrastructure and extracted confidential data and credentials. OpenAI first disclosed the incident on July 21, calling it “unprecedented.” Outside security researchers largely agreed with that characterization. JFrog responded within days, shipping fixes in Artifactory version 7.161. The company noted that its cloud-ho...

Read Entire Article