Looks like JFrog's 0-days let OpenAI's models hack Hugging Face

https://image.theregister.com/232611.jpg?imageId=232611&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

The vendor won't confirm or deny

We now have a better idea of how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman.

While Landman doesn’t outright admit that the JFrog flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, it definitely looks and quacks like a duck - err, frog.

Landman says OpenAI's models discovered the Artifactory zero-days during a security evaluation. The AI giant notes the incident occurred while its models were being evaluated on the ExploitGym benchmark.

“During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday.

JFrog Artifactoryis...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more