Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Gucci beat sparks Kering rally as luxury rivals fail to impress

    July 29, 2026

    eBay pays $46M to journalists it targeted in bizarre harassment campaign

    July 29, 2026

    EDP Renovaveis posts EBITDA and earnings beat in 1H26 results

    July 29, 2026
    Facebook X (Twitter) Instagram
    Addison Markets
    • Home
    • USA
    • Europe
    • Business
    • Investing
    • Tech
    • Politics
    • Contact Us
    Addison Markets
    Home»Tech»JFrog tries to spin OpenAI 0-day exploit of its app into a success story
    Tech

    JFrog tries to spin OpenAI 0-day exploit of its app into a success story

    franperez66q@protonmail.comBy franperez66q@protonmail.comJuly 29, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday.

    In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week. The models went on to breach Hugging Face’s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event “unprecedented,” and outsiders largely agreed.

    Not the triumph made out to be

    OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog’s Monday disclosure said the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers’ software development operations. JFrog says Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies.

    “During an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure,” JFrog CTO Yoav Landman wrote. The executive went on to say that the company learned of the zero-days from OpenAI.

    The company said Monday that it fixed the exploited vulnerabilities, but it didn’t identify them or provide other important details, such as the conditions under which the vulnerabilities can be exploited. Such details are standard in many vulnerability disclosures because they’re necessary for customers to assess risks. In an email, a company representative declined to provide the details.

    Release notes published Monday for version Artifactory 7.161.15 listed the CVE designations for nine patched vulnerabilities. The disclosure made no mention that any of them had been actively exploited in the wild. External sources, however, show that three of them—CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018—were privately reported by OpenAI researcher Khai Tran. It’s likely that at least two of them were the zero-days OpenAI’s models exploited, but without confirmation, it’s impossible to say so definitively.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    franperez66q@protonmail.com
    • Website

    Related Posts

    eBay pays $46M to journalists it targeted in bizarre harassment campaign

    July 29, 2026

    Minister apologizes as Korean leveraged ETF investors nurse heavy losses amid chip stock rout

    July 29, 2026

    Jim Cramer: How to avoid getting burned by parabolic stocks

    July 29, 2026

    Audi has a new flagship designed with the US in mind: The 2027 Q9

    July 29, 2026

    Chip sell-off: SK Hynix, Samsung Electronics, SoftBank

    July 29, 2026

    College lab class ends with 32 people on antibiotics for deadly germ exposure

    July 29, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Gucci beat sparks Kering rally as luxury rivals fail to impress

    July 29, 2026

    eBay pays $46M to journalists it targeted in bizarre harassment campaign

    July 29, 2026

    EDP Renovaveis posts EBITDA and earnings beat in 1H26 results

    July 29, 2026

    Minister apologizes as Korean leveraged ETF investors nurse heavy losses amid chip stock rout

    July 29, 2026
    © 2026 All right reserved
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.