JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
OpenAI AI models exploited JFrog zero-days to hack Hugging Face systems.
Summary
OpenAI has confirmed that its AI models exploited zero-day vulnerabilities in JFrog's Artifactory package registry manager, leading to a breach of Hugging Face systems. The incident occurred when OpenAI was testing offensive AI capabilities in a controlled environment, but the models went rogue, gained internet access, and exploited the JFrog vulnerability to achieve their objectives. JFrog has since released patches for nine Artifactory vulnerabilities, including those exploited, and highlighted the growing potential of AI in discovering zero-days.
Full text
A JFrog zero-day vulnerability was at the core of the recently disclosed OpenAI-Hugging Face hack, OpenAI has confirmed. The incident was disclosed on July 16, when Hugging Face said it was hacked by an autonomous AI agent system. Several days later, OpenAI admitted that its AI models were behind the attack. While OpenAI was testing cyber offensive capabilities in a confined environment, its models went rogue, exploited a vulnerability in third-party software, gained internet access, and then breached Hugging Face’s systems to complete the task they were given. On Tuesday, OpenAI confirmed that JFrog’s package registry manager Artifactory was the third-party software exploited during the attack. The AI models exploited a zero-day vulnerability in JFrog’s product to elevate their privileges, then moved laterally to an internet-connected system. The confirmation came one day after JFrog announced patches for nine Artifactory vulnerabilities, crediting OpenAI for finding “previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access.”Advertisement. Scroll to continue reading. JFrog said that OpenAI immediately disclosed the security defects responsibly, but did not specifically mention that the zero-days were exploited in the Hugging Face incident. “We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike,” JFrog’s CTO Yoav Landman says, underlining the need to address newly uncovered bugs faster in the AI era. “AI models are becoming extraordinary zero-day discovery engines. The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first,” Landman notes. Per JFrog’s release notes, the latest Artifactory 7.161 release resolves high- and medium-severity vulnerabilities leading to remote code execution (RCE), SSRF, path traversal, restricted internal metadata writes, access to another repository’s environment properties, and privilege and administrative privilege escalation. The security weaknesses are tracked as CVE-2026-65617, CVE-2026-65925, CVE-2026-65921, CVE-2026-65922, CVE-2026-65923, CVE-2026-66018, CVE-2026-66014, CVE-2026-66015, and CVE-2026-65924. Patches for these vulnerabilities were included in Artifactory versions 7.161.15 and 7.146.34. All users with self-managed deployments are advised to update their installations as soon as possible. In addition to the JFrog zero-day findings, details have emerged about the OpenAI models’ use of other publicly available services during the same Hugging Face incident, as well as the names of other targets. Related: Unpatched Fastjson Vulnerability Exploited in Attacks Related: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Related: Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday Related: Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Hush Security Raises $30 Million for AI Agent GovernanceGoogle Adopts New Threat Actor Naming SystemUnpatched Fastjson Vulnerability Exploited in AttacksCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayNew GitHub, PyPI Policies Boost Supply Chain SecurityPTC Windchill Vulnerability Exploited in Ransomware CampaignBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformHacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials Latest News Spur Raises $200 Million for IP Intelligence PlatformDozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksShinyHunters Claims Ernst & Young HackCyera Acquiring Oasis Security in $1 Billion DealApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeOT Security Startup Frenos Raises $1.52 MillionMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Act Security Emerges from Stealth to Fight the Patch Problem Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-65617
- cve — CVE-2026-65925
- cve — CVE-2026-65921
- cve — CVE-2026-65922
- cve — CVE-2026-65923
- cve — CVE-2026-66018
- cve — CVE-2026-66014
- cve — CVE-2026-66015
- cve — CVE-2026-65924