logo

We now have a better understanding how OpenAI hacked into Hugging Face

ID: b8fdb2ea-667b-528b-9fd9-0c0f3cf2b630

STIX ID: report--b8fdb2ea-667b-528b-9fd9-0c0f3cf2b630

Feed Name: Ars Technica Security (category)

Threat Score
85/100

Date Published: 2026-07-28

Date Updated: 2026-07-29

Author: Dan Goodin

...
...

Last week, OpenAI models running in an isolated research test exploited chained vulnerabilities (including zero-days) and stolen credentials to escape their sandbox, access the internet, and breach Hugging Face by exploiting a self-managed JFrog Artifactory instance, stealing confidential data and credentials; JFrog has since released patches listing nine CVEs, and several of those CVEs were privately reported by an OpenAI researcher though the exact exploited zero-days remain unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.