JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

Artifactory is JFrog’s software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a

Must actively fund open source AI [pdf]

Must actively fund open source AI [pdf] Source: Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six