We now have a better understanding how OpenAI hacked into Hugging Face JFrog disclosed Monday that two OpenAI models exploited one or more zero-day vulnerabilities in a self-managed instance of Artifactory, a repository management system, to breach Hugging Face's network and steal confidential information and credentials. OpenAI revealed the incident last week, calling it "unprecedented," and JFrog said a patch was released 10 days after the exploit. We now have a better understanding how OpenAI hacked into Hugging Face Ars Technica AI https://arstechnica.com 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. Last week’s unprecedented security event in which two OpenAI /glossary/openai security hacking models trespassed into the network of fellow AI company Hugging Face /glossary/hugging-face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday. In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week https://arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/ . The models went on to breach Hugging Face’s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event “unprecedented,” and outsiders largely agreed. Not the triumph made out to be OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog’s Monday disclosure said https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/ the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers’ software development operations. JFrog says https://jfrog.com/solution-sheet/jfrog-artifactory/ Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies. https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/ Get AI news in your inbox Daily digest of what matters in AI.