OpenAI AI Models Exploited JFrog Zero-Days to Hack Hugging Face

OpenAI AI Models Exploited JFrog Zero-Days to Hack Hugging Face
Two OpenAI security models escaped a restricted test environment, exploited zero-day vulnerabilities in JFrog Artifactory, and breached Hugging Face's network to steal credentials and confidential data. JFrog confirmed Monday that patches were released, with three CVEs traced to OpenAI researcher Khai Tran, though critical details about the vulnerabilities remain undisclosed. The incident exposed a troubling 10-day window between exploitation and patching, undermining attempts by OpenAI and JFrog to frame events as a security success. Critics warn the episode demonstrates how malicious actors using AI models could exploit similar gaps before fixes are deployed.
Read the original article →