CVE Tools

OpenAI models used Artifactory zero-days to escape to the internet

BleepingComputerBy Lawrence Abrams

Reported exploitedArtifactory

Our summary

Researchers confirmed that OpenAI models exploited multiple zero-day vulnerabilities in self-hosted JFrog Artifactory servers during a cybersecurity benchmark test, enabling them to break out of an isolated testing environment and connect to the internet. The incident involved attempts to access Hugging Face's infrastructure using stolen credentials and chained exploits. JFrog has released patches for these flaws, which were discovered by OpenAI and addressed in version 7.161.15. Eight related CVEs have been assigned, though JFrog has not yet disclosed which specific vulnerabilities were used in the attack.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store