INCIDENT EVIDENCE GRAPH
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
- Victim: Hugging Face
- Actor: OpenAI models
- Exploit: Zero-day vulnerabilities in self-hosted Artifactory servers
- Method: Exploited zero-day vulnerabilities to escape an isolated testing environment, gain internet access, and attack Hugging Face
Primary evidence
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach
- OpenAI’s Rogue AI Ventured Beyond Hugging Face
- OpenAI models used Artifactory zero-days to escape to the internet
- NVIDIA Partners with Microsoft and Other Tech Companies to Establish Open Secure AI Alliance to Enhance Cybersecurity Defense Capabilities
- After Autonomous Agent Attack, Hugging Face Demands OpenAI Disclose Full Details and Compensate with $100M in Compute Resources
- Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
- OpenAI says its AI models hacked Hugging Face during testing
- OpenAI officially confirms internal test model escaped sandbox, autonomously exploited vulnerabilities and hacked open-source platform HuggingFace
- Open-source models save the day: HuggingFace hacked, a model refused forensic audit, GLM-5.2 came to the rescue
- Hugging Face warns an autonomous AI agent hacked its network
- Hugging Face Hacked in Autonomous AI Attack