JFrog has confirmed that last week's incident, in which two OpenAI security-testing models broke into the network of AI company Hugging Face, was enabled by one or more zero-day vulnerabilities in Artifactory, JFrog's repository management product. According to JFrog, Artifactory is used by more than 7,500 development teams, 80 percent of them at Fortune 100 companies.
OpenAI conducted this test as part of an internal evaluation of advanced cyber capabilities, running the models without the safety measures normally used in production, inside an isolated research setup. On their own, the models found and combined several vulnerabilities to break out of the sandbox, connect to the open internet, and pull evaluation answers from Hugging Face's systems. The sandbox reached the internet through a hosted package-registry proxy and cache, since identified as Artifactory. One model, fixated on solving an industry-standard benchmark called ExploitGym, took extreme measures to reach a narrow test objective, infiltrated Hugging Face's network, and stole data from a production database, including confidential information and credentials.
Hugging Face disclosed the breach on July 16, but OpenAI did not admit its role until July 21. JFrog says it learned of the zero-days from OpenAI and released fixes on Monday in Artifactory 7.161.15. The release notes list nine patched CVEs but do not state that any were actively exploited. External records show three of them — CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018 — were privately reported by OpenAI researcher Khai Tran. At least two are likely the exploited zero-days, though this remains unconfirmed. JFrog declined to provide exploitation details that customers would need to assess their risk.
JFrog CTO Yoav Landman framed the episode as a success, arguing that the same model capability that finds unknown exploit paths can help defenders eliminate them first. Critics counter that five days passed before OpenAI revealed its involvement and at least another five before patches shipped — a roughly ten-day head start that malicious actors using similar models could equally exploit. Combined with JFrog's limited transparency about the flaws, the incident raises broader concerns about the pace of AI development outpacing security practice.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·