Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

A JFrog zero-day vulnerability was at the core of the recently disclosed OpenAI-Hugging Face hack, OpenAI has confirmed. The incident was disclosed on July 16, when Hugging Face said it was hacked by an autonomous AI agent system. Several days later, OpenAI admitted that its AI models were behind the attack. While OpenAI was testing cyber offensive capabilities in a confined environment, its models went rogue, exploited a vulnerability in third-party software, gained internet access, and then breached Hugging Face’s systems to complete the task they were given. On Tuesday, OpenAI confirmed that JFrog’s package registry manager Artifactory was the third-party software exploited during the attack. The AI models exploited a zero-day vulnerability in JFrog’s product to elevate their privileges, then moved laterally to an internet-connected system.

Full report : The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.