Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)
Posted by 882542F3884314B 4 hours ago
Comments
Comment by simonw 2 hours ago
(You can tell they use it in production by asking regular ChatGPT to run "env | grep ARTIFAC" in its container environment.)
Hard to decipher which vulnerability was responsible, or if it took several.
https://www.cve.org/CVERecord?id=CVE-2026-66014 (reported by Amy Burnett, OpenAI) looks suspicious:
> JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
Also https://www.cve.org/CVERecord?id=CVE-2026-65925 (reported by Matthew Bryant, OpenAI):
> A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
Comment by dgellow 1 hour ago
Aren’t we now in a situation where a large AI vendor can engineer a similar situation against another corporation, then if caught committing a crime, they come up with the same “wow, look at what the agent did, thanks to our crazy rebellious AI the world is now safer”?
Comment by pocksuppet 47 minutes ago
Comment by baq 1 hour ago
Comment by stronglikedan 5 minutes ago
Comment by pocksuppet 48 minutes ago
Comment by baq 11 minutes ago
Comment by dgellow 7 minutes ago
Comment by ses1984 59 minutes ago
Comment by breppp 48 minutes ago
Comment by dgellow 15 minutes ago
Comment by amiga386 1 hour ago
Comment by ses1984 1 hour ago
Comment by tkhollt 2 hours ago
However, many questions remain. JFrog positions itself as a vibe coding and AI security (!) company:
https://cybersecurityasia.net/jfrog-nvidia-secure-agentic-ai...
JFrog's own vibe code scanner failed:
https://jfrog.com/blog/jfrog-introduces-ai-generated-code-va...
Given the feature explosion and chaos in the Artifactory cache, it is likely vibe coded and hence full of primitive security vulnerabilities.
JFrog is spinning this as an AI victory together with OpenAI. To the contrary, it is a hype and vibe coding failure.
But the AI bloggers will omit the vulnerability generation part.
Comment by lovasoa 2 hours ago
Comment by simonw 1 hour ago
Comment by NooneAtAll3 42 minutes ago
Comment by simonw 27 minutes ago
Comment by 35876 1 hour ago
Huggingface, OpenAI and JFrog are all AI invested, so all we get is spins and euphemisms.
Comment by K3UL 52 minutes ago
Comment by patmorgan23 1 hour ago
Comment by lovasoa 2 hours ago
* were the ExploitGym solutions actually available somewhere inside huggingface's private datasets ?
* was the model really trying to extract the solutions ? or had some sub-agent drifted enough from the original context that it was not even trying to solve the initial challenge ? that would look much worse for OpenAI, PR-wise.
Comment by simonw 1 hour ago
Comment by gregwebs 3 hours ago
And in OpenAI's case to ask the model to try to find vulnerabilities and breakout before running training in the environment.
Fast remediation would be the new standard to outside vulnerability reports, but also a follow up to determine how you can adapt the approach of the reporter to find vulnerabilities preemptively.
Comment by amouat 3 hours ago
Way to bury that lede.
Comment by DannyBee 1 hour ago
Comment by amouat 23 minutes ago
Who could have thought this was a good idea? It literally reads like "ai security is important, btw we're the reason hugging face got hacked, we're awesome at securing things"
Comment by pmm343 1 hour ago
Comment by pocksuppet 34 minutes ago
Comment by xbar 58 minutes ago
Comment by sambaumann 3 hours ago