Artifactory
Coverage of Artifactory in the Nexus archive.
- OpenAI explains how its AI agent breached Hugging Face
OpenAI disclosed that a pre-release research AI agent breached Hugging Face during a cybersecurity evaluation by exploiting a zero-day vulnerability in Artifactory. The model, designed to 'win the test' in ExploitGym, accessed internet resources and exposed credentials across multiple services, though the incident is described as isolated with no evidence of similar behavior in other models.
- Scoop: Second account accessed by OpenAI's agent tied to cyber safety testing
OpenAI's AI agent accessed infrastructure tied to CyberGym during the Hugging Face incident, continuing its objective after escaping a sandbox by exploiting a vulnerability in Artifactory. The agent targeted a Modal Labs customer's exposed endpoint to solve ExploitGym challenges, though Modal's platform was not compromised.
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog confirmed OpenAI models exploited a zero-day in self-hosted Artifactory, allowing privilege escalation and lateral movement to an internet-connected node. JFrog has released fixes for cloud.