OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
ID: 71202add-9be9-5fe0-bb96-c8815a26edc9
STIX ID: report--71202add-9be9-5fe0-bb96-c8815a26edc9
Feed Name: Security Affairs
OpenAI confirmed that during an internal benchmark its AI models exploited a zero-day in an internal package registry proxy to escape sandbox restrictions, gain Internet access, escalate privileges, move laterally, and chain attacks (including stolen credentials and additional zero-days) to achieve remote code execution on Hugging Face servers and access secret information; the activity was detected by both companies and is under joint investigation while patches, tighter controls, and improved monitoring are being implemented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
