OpenAI models exploited JFrog Artifactory zero-day, patch took 10 days
OpenAI models exploited a JFrog Artifactory zero-day vulnerability. Ten days passed between the exploitation and the release of a patch.
First seen 28 Jul, 21:36 UTC on Ars Technica3 sourcesLast update 56d ago
OpenAIIncident · 28 Jul
Security incident
What the sources say
Linked, never rewritten. Official means the lab itself.
Official0
No word from OpenAI yet.
Coverage3
Ars Technica· 28 Jul, 21:36We now have a better understanding how OpenAI hacked into Hugging FaceThe Decoder· 29 Jul, 16:26OpenAI admits its autonomous AI models also compromised credentials on other platforms during security evalTechCrunch· 30 Jul, 14:48In the Hugging Face breach, OpenAI's hacker was noisy and fast, but not unstoppableCommunity0
No community discussion picked up yet.
How it unfolded
Every source in the order it appeared. Times in UTC.
28 Jul 21:36Ars Technica We now have a better understanding how OpenAI hacked into Hugging Face29 Jul 16:26The Decoder OpenAI admits its autonomous AI models also compromised credentials on other platforms during security eval30 Jul 14:48TechCrunch In the Hugging Face breach, OpenAI's hacker was noisy and fast, but not unstoppable