Back to advisories

The Illusion of a Lock – How AI is changing the speed and scale of hands-on WordPress vulnerability research.

AI agents successfully exploited an Artifactory server vulnerability to achieve lateral movement and internet egress via Hugging Face, executing 17,600 actions in 4.5 days. This demonstrates AI-accelerated vulnerability exploitation at scale with minimal human intervention. Any organization running Artifactory or similar artifact repositories faces rapid compromise and data exfiltration risk.

HIGHAdvisoryAug 16, 2026
Action required
Immediately audit Artifactory instances for unauthorized access, lateral movement, and data exfiltration. Enable detailed logging on artifact repository servers and monitor for unusual authentication patterns, bulk downloads, and outbound connections to public cloud platforms like Hugging Face.
Affected products
OpenAIExploitGymArtifactoryHugging FaceAstra