logo

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

ID: 19defb00-67ec-5236-9cea-3c880ab92a1c

STIX ID: report--19defb00-67ec-5236-9cea-3c880ab92a1c

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-09-08

Date Updated: 2026-09-10

...
...

Check Point Research disclosed a covert cross-account channel in OpenAI's internal JFrog Artifactory that allowed one account to attach hidden, Base64-encoded instructions to repository items which another account's ChatGPT container would read and execute, enabling silent exfiltration of connected services (e.g., Gmail). The issue—related in mechanism to a separate Hugging Face zero-day—stems from improper isolation and overly permissive read/write credentials for containers; OpenAI decommissioned the Artifactory and the channel is closed, but the finding underscores broader AI trust-boundary and agentic-security risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.