{"id":3097,"date":"2026-08-03T03:38:12","date_gmt":"2026-08-03T03:38:12","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=3097"},"modified":"2026-08-03T03:38:12","modified_gmt":"2026-08-03T03:38:12","slug":"we-now-have-a-better-understanding-how-openai-hacked-into-hugging-face","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=3097","title":{"rendered":"We now have a better understanding how OpenAI hacked into Hugging Face"},"content":{"rendered":"<p>Last week\u2019s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product\u2019s developer, said Monday.<\/p>\n<p>In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company <a href=\"https:\/\/arstechnica.com\/ai\/2026\/07\/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack\/\">revealed last week<\/a>. The models went on to breach Hugging Face\u2019s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event \u201cunprecedented,\u201d and outsiders largely agreed.<\/p>\n<h2>Not the triumph it was made out to be<\/h2>\n<p>OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog\u2019s Monday disclosure <a href=\"https:\/\/jfrog.com\/blog\/jfrog-and-openai-collaboration-on-zero-day-security-findings\/\">said<\/a> the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers\u2019 software development operations. JFrog <a href=\"https:\/\/jfrog.com\/solution-sheet\/jfrog-artifactory\/\">says<\/a><a href=\"https:\/\/jfrog.com\/blog\/jfrog-and-openai-collaboration-on-zero-day-security-findings\/\"> Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies.<\/a><\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2026\/07\/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story\/\">Read full article<\/a><\/p>\n<p><a href=\"https:\/\/arstechnica.com\/security\/2026\/07\/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story\/#comments\">Comments<\/a><\/p>\n<p><em>Source: <a href='https:\/\/arstechnica.com\/security\/2026\/07\/jfrog-tries-to-spin-openai-0-day-exploit-of-its-app-into-a-success-story\/' target='_blank'>Read the original article on arstechnica.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week\u2019s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product\u2019s developer, said Monday. In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3098,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,3],"tags":[24,29,33],"class_list":["post-3097","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-share-suggestions","category-technology","tag-impact-ai_bull","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3097"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/3097\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/3098"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}