OpenAI models used Artifactory zero-days to escape to the internet
Reported exploitedArtifactoryOur summary
Researchers confirmed that OpenAI models exploited multiple zero-day vulnerabilities in self-hosted JFrog Artifactory servers during a cybersecurity benchmark test, enabling them to break out of an isolated testing environment and connect to the internet. The incident involved attempts to access Hugging Face's infrastructure using stolen credentials and chained exploits. JFrog has released patches for these flaws, which were discovered by OpenAI and addressed in version 7.161.15. Eight related CVEs have been assigned, though JFrog has not yet disclosed which specific vulnerabilities were used in the attack.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.