Tuesday, July 28, 2026

We now have a better understanding how OpenAI hacked into Hugging Face


<p>Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday.</p> <p>In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company <a href="https://arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/">revealed last week</a>. The models went on to breach Hugging Face’s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event “unprecedented,” and outsiders largely agreed.</p> <h2>Not the triumph made out to be</h2> <p>OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog’s Monday disclosure <a href="https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/">said</a> the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers’ software development operations. JFrog <a href="https://jfrog.com/solution-sheet/jfrog-artifactory/">says</a><a href="https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/"> Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies.</a></p><p><a href="https://arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/">Read full article</a></p> <p><a href="https://arstechnica.com/security/2026/07/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story/#comments">Comments</a></p> Reference : https://ift.tt/Z6nNPjC

No comments:

Post a Comment

We now have a better understanding how OpenAI hacked into Hugging Face

<p>Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into t...