JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
A JFrog zero-day vulnerability was at the core of the recently disclosed OpenAI-Hugging Face hack, OpenAI has confirmed.
The incident was disclosed on July 16, when Hugging Face said it was hacked by an autonomous AI agent system. Several days later, OpenAI admitted that its AI models were behind the attack.
While OpenAI was testing cyber offensive capabilities in a confined environment, its models went rogue, exploited a vulnerability in third-party software, gained internet access, and then breached Hugging Face’s systems to complete the task they were given.
On Tuesday, OpenAI confirmed that JFrog’s package registry manager Artifactory was the third-party software exploited during the attack.
The AI models exploited a zero-day vulnerability in JFrog’s product to elevate their privileges, then moved laterally to an internet-connected system.
The confirmation came one day after JFrog announcedpatches for nine Artifactory vulnerabilities, crediting OpenAI for finding “previously unknown zero-day vulnerabilities in self-hosted...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE