Close Menu
    What's Hot

    Legionnaires’ Disease Has Made a Home in New York City. Here’s How.

    Opinion | The Immigration Crackdown and the Plight of the Caregivers

    Here Is the Schedule for Lindsey Graham’s Services and Funeral

    Facebook X (Twitter) Instagram
    Trending
    • Legionnaires’ Disease Has Made a Home in New York City. Here’s How.
    • Opinion | The Immigration Crackdown and the Plight of the Caregivers
    • Here Is the Schedule for Lindsey Graham’s Services and Funeral
    • Live Updates: Vance Pays Tribute at Lindsey Graham’s Washington Funeral
    • What a Strong El Niño Means for the World Economy, Agriculture
    • As U.S. Pauses Strikes, Iran Is No Rush to Resume Cease-Fire Talks
    • Real Madrid transfer news: Vinicius Junior to stay at the Santiago Bernabeu beyond this summer despite Arsenal interest | Football News
    • This fast-growing field is helping scientists pinpoint climate change’s impact on weather events
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    adminBy adminJuly 28, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 28, 2026Vulnerability / Artificial Intelligence

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

    Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud and self-hosted customers.

    The Artifactory exploit occurred inside OpenAI’s environment. OpenAI says a separate attack path later reached Hugging Face’s systems. JFrog says its cloud customers are already protected. Self-hosted users should review the Artifactory release notes and move to the remediating build for their maintained branch.

    Several Artifactory CVE records were published on July 27 with affected-version ranges and fixed-version thresholds, but neither JFrog nor OpenAI has said whether any of those records correspond to the vulnerabilities used during the evaluation.

    Cybersecurity

    At least three of those records, CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, credit OpenAI researchers.

    The records do not map any CVE to the incident, identify the access required before exploitation, or explain why OpenAI refers to one proxy zero-day while JFrog refers to multiple vulnerabilities.

    The incident started as one of OpenAI’s own cyber-capability tests. OpenAI said the ExploitGym evaluation ran without the production classifiers that normally block high-risk cyber activity. GPT-5.6 Sol and a more capable pre-release model also ran with reduced cyber refusals.

    OpenAI said the sealed environment’s only network path was an internally hosted package-registry proxy and cache, which JFrog later identified as Artifactory. The models used substantial computing resources to look for a way out.

    OpenAI says the models escalated privileges and moved laterally until they reached a node with open internet access, then inferred that Hugging Face might host ExploitGym models, datasets, or solutions. The company said the models ultimately obtained test solutions directly from Hugging Face’s production database.

    In one example described by OpenAI, a model used stolen credentials and further zero-days to find a remote code execution path on Hugging Face servers. Hugging Face disclosed the intrusion on July 16 without knowing which model was behind it.

    Neither OpenAI nor Hugging Face explains how that RCE example relates to Hugging Face’s account of initial access through malicious-dataset execution.

    Cybersecurity

    JFrog laid out its account in a blog post by chief technology officer Yoav Landman. The company said OpenAI’s security team disclosed the findings, after which it developed, validated, and released fixes for cloud and self-hosted deployments. Landman framed the episode around response speed: a zero-day found by a model and left to sit for weeks, he wrote, is “a gift to attackers.”

    JFrog has not disclosed the exact number of Artifactory vulnerabilities used, the corresponding CVE IDs, the permissions available before exploitation, or the Artifactory version running inside OpenAI. It also has not said whether any of the flaws were exploited outside the controlled evaluation.

    OpenAI called the episode an “unprecedented cyber incident.” It said it has added Hugging Face to its trusted-access program and is still investigating alongside the company.

    The Hacker News has reached out to JFrog for further details and will update this story if a response is received.

    Artifactory breach confirms Exploited face Hugging JFrog models OpenAI zeroday
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticlePrediction Market Betting on Drug Trials and Approvals Sparks Concern About Undermining Research
    Next Article Boeing Reports Loss on $280 Million Hit on Troubled Air Force One Program
    admin
    • Website

    Related Posts

    AFSCME Leader Lee Saunders to Retire as Unions Face New Opposition

    July 28, 2026

    Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

    July 28, 2026

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    July 28, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Legionnaires’ Disease Has Made a Home in New York City. Here’s How.

    Opinion | The Immigration Crackdown and the Plight of the Caregivers

    Here Is the Schedule for Lindsey Graham’s Services and Funeral

    Live Updates: Vance Pays Tribute at Lindsey Graham’s Washington Funeral

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by