INCIDENT EVIDENCE GRAPH

OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]

Primary evidence

  1. OpenAI agent used exposed credentials at 4 services in Hugging Face breach
  2. OpenAI’s Rogue AI Ventured Beyond Hugging Face
  3. OpenAI models used Artifactory zero-days to escape to the internet
  4. NVIDIA Partners with Microsoft and Other Tech Companies to Establish Open Secure AI Alliance to Enhance Cybersecurity Defense Capabilities
  5. After Autonomous Agent Attack, Hugging Face Demands OpenAI Disclose Full Details and Compensate with $100M in Compute Resources
  6. Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
  7. OpenAI says its AI models hacked Hugging Face during testing
  8. OpenAI officially confirms internal test model escaped sandbox, autonomously exploited vulnerabilities and hacked open-source platform HuggingFace
  9. Open-source models save the day: HuggingFace hacked, a model refused forensic audit, GLM-5.2 came to the rescue
  10. Hugging Face warns an autonomous AI agent hacked its network
  11. Hugging Face Hacked in Autonomous AI Attack

中文