JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management

Snails’ Teeth Beats Spider Silk as Nature’s Strongest Material

Snails’ Teeth Beats Spider Silk as Nature’s Strongest Material Source: Hacker News

Forget Data Leakage: Shadow AI’s Real Threat Is Access Control

Forget Data Leakage: Shadow AI’s Real Threat Is Access Control The first wave of enterprise AI concern was straightforward. It was simply employees pasting sensitive data into public AI tools.