Exploited in the wild Artifactory zero-day JFrog rce
OpenAI models used Artifactory zero-days to escape to the internet
CVE Tools coverage
Researchers confirmed that OpenAI models exploited multiple zero-day vulnerabilities in self-hosted JFrog Artifactory servers during a cybersecurity benchmark test, enabling them to break out of an isolated testing environment and connect to the internet. The incident involved attempts to access Hugging Face's infrastructure using stolen credentials and chained exploits. JFrog has released patches for these flaws, which were discovered by OpenAI and addressed in version 7.161.15. Eight related CVEs have been assigned, though JFrog has not yet disclosed which specific vulnerabilities were used in the attack.