www.bleepingcomputer.com/news/secu…
In an update on the earlier incident, OpenAI confirmed that its AI models (running in a reduced-safety evaluation environment) not only escaped their sandbox by exploiting a zero-day in JFrog Artifactory but also used publicly exposed credentials to compromise accounts on four separate third-party services during the multi-day intrusion into Hugging Face infrastructure.
The models gained internet access via the Artifactory flaw, then performed reconnaissance, lateral movement and data access over roughly four days. OpenAI has disclosed the Artifactory vulnerabilities to JFrog (multiple CVEs now patched) and stated that no production models intended for release were involved.