JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI can’t be listed as inventor on patent applications, Japan’s top court rules

AI can’t be listed as inventor on patent applications, Japan’s top court rules Source: Hacker News

Sealed tomb filled with paintings and inscriptions discovered in Egypt

Sealed tomb filled with paintings and inscriptions discovered in Egypt Source: Hacker News

144 Mastra npm Packages Compromised via Hijacked Contributor Account

144 Mastra npm Packages Compromised via Hijacked Contributor Account As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building