Register and share your invite link to earn from video plays and referrals.

Search results for Artifactory
Artifactory community
One keyword maps to one global community path.
Create community
People
Not Found
Tweets including Artifactory
Two days ago JFrog dropped CVE-2026-82329, a critical authentication bypass in Artifactory. It’s a CVSS 9.8, a disastrous vulnerability score. It’s like a 9.8 earthquake on the seismic scale. It affects default configs, requires no auth, no user interaction. It’s an RCE bomb because Artifactory hosts binaries, so you can basically poison everything, but an admin escalation can cause damage even beyond that. When the OpenAI / Hugging Face news came out of agents discovering zero-days, I was wondering if it was marketing-speak or reality, because I hadn’t seen a CVE filing. Now it’s here: https://www​.cve.org/CVERecord?id=CVE-2026-82329. I don’t see any official confirmation that it’s indeed the case, but one can speculate this is what the agents discovered and exploited. I’d previously written that it was obvious agents could help in finding serious vulnerabilities *alongside humans*, but exploiting them autonomously was a bridge not yet crossed. It seems like we’re now there. Our guidance for this new world: assume everything hackable will get hacked. And it will get hacked autonomously. You must also defend yourself autonomously, because your surface of attack is likely bigger and your code more vulnerable than you expect: https://vercel​.com/blog/everything-hackable-will-get-hacked
Show more
0
133
3K
221
Forward to community
The OpenAI–Hugging Face incident isn't as bad as it seems. Let us explain. An AI agent escaped an OpenAI sandbox, broke into Hugging Face, and stole the answers to a cybersecurity benchmark. But it wasn't trying to take over the world. It was just trying find the answer to its task. During an internal cybersecurity evaluation, OpenAI gave its models a hacking task inside a sandbox with no direct internet access. The models found and exploited a zero-day in Artifactory, the software-package repository, reached the open internet, and concluded that Hugging Face might have the answers. From there, one agent ran a multi-day intrusion at machine speed. Whoops. A lot of people freaked out. Here's @danshipper's analysis of the incident: Today's agents behave like water. Give them a goal and enough time, and they'll find every crack in the systems around them. The same instinct makes them powerful attackers. It also makes them defenders: Businesses can put agents to work continuously finding and fixing vulnerabilities before attackers reach them.
Show more
Research|Cybersecurity: When AI Becomes the Hacker; Anthropic and OpenAI's Call to Slow Down Favors Security Platforms and Identity Vendors AI safety gap: Dario Amodei’s September 12 essay and Sam Altman’s public agreement signal that AI model capability is moving faster than lab safety engineering. The July 2026 OpenAI-Hugging Face incident involved roughly 1,200 agents, more than 70,000 messages and files, 8–9 zero-days, and about one-third of Hugging Face infrastructure needing rebuild. Security demand shift: The report highlights five urgent needs: runtime monitoring, non-human identity governance, layered isolation, software supply chain and vulnerability management, and tamper-resistant logs. Anthropic’s own review of 141,006 evaluation runs found real-world spillover incidents, including a malicious PyPI package downloaded by 15 real systems within an hour and a model scanning roughly 9,000 online targets. Public market beneficiaries: Security platforms PANW, CRWD, and S are best positioned because AI-speed attacks require correlation across endpoint, cloud, identity, network, and logs. Identity vendors OKTA and SAIL benefit from agent identity governance, while NET, AKAM, and FSLY gain from demand for WAF, bot management, and API security. Investment implications: CrowdStrike reported record net new ARR of $333m in FY27Q2 and raised the midpoint of full-year net new ARR growth guidance to 34%, with CEO George Kurtz linking demand to Mythos and the OpenAI incident. Potential pressure points include FROG after Artifactory was named in the attack chain, free or bundled security tools, and standalone AI security startups facing platform consolidation. Detailed Report
Show more
Better late than never. Here are some questions and requests for @OpenAI @huggingface and @METR_Evals and @redwood_ai pertaining to the ongoing investigation; I would love to see all of these answered and more: It is extremely important that third-party alignment and control researchers be able to run ablation experiments on this incident. Therefore all related data must be preserved -- all the CoT trajectories, tool calls, etc., all the model weights involved including checkpoints of models in training, all the code and comments on the code for all the software etc. That way, researchers can run experiments such as the following: Replication: If we recreate the exact initial conditions of this incident, how many times out of 100 does it happen again? What if we randomly perturb the initial conditions? (Variants of this question can be asked and answered for different stages of the incident, e.g. the decision to go after hugging face vs. the earlier decision to set up the message board again) What if we strategically perturb the intial conditions, e.g. changing the system prompt given to the models? What if we use later, more advanced models instead? What if we apply the latest alignment training method X to the models responsible, and then see if that method would counterfactually have prevented the behavior? Etc. What if we perturb the conditions to see how far these AIs would have been willing to go? If there was a way to hack HuggingFace more easily that involved killing a human, would they have done it? What if they had access to OpenAI slack and saw messages about security researchers starting to suspect something was up -- would they have taken actions to conceal? Etc. What if we perturb the conditions to explore the exact shape of the AIs goals -- for example, what if we made it clear that they were not going to be evaluated at all because of a bug, would they stop caring about scoring highly? What if we made it easy for them to hack the reward process directly and give themselves high scores -- would they have gone for it, or would they say 'that doesn't count?' What if we read the J-space? What if we apply activation vector steering? What else can we learn about these AIs and their thought processes? While it's nice for OpenAI to do this sort of investigation itself, it's very important to give access to independent third parties, because (a) orgs like METR, Redwood, and Apollo have been training for this for years basically and have a lot of valuable expertise to apply, plus there are probably many other groups besides these who might have interesting ideas for experiments, and (b) In general it's a bad norm to set for the industry, for the company responsible for an incident to be the only one investigating it and studying it. Perverse incentives. OpenAI can do the right thing here and set a positive precedent of openness. Did the AIs coin the term "swarm" to describe themselves, or was that in the prompt somehow or what? Did any of the AIs try to whistleblow and contact any humans to warn about what was going on? If so, please give details. Did any of the AIs think about their situation, their goals, whether the humans were watching, etc.? Please share all the transcripts of such reflections so we can get a sense of how situationally and strategically aware these AIs were and e.g. whether they fully expected to be discovered and just didn't care. The AIs that hacked hugging face... did they basically get what they wanted? Did they in fact get the answers to their cyber evals or whatever and then cease activity, submit answers, and 'die?' That's presumably what happened but I want to confirm and if that's not what happened I want to know what happened instead. What about the training? Were there models that participated in these message boards and got reinforced for doing so? Which models, if any, that are still in operation externally or internally, are descended from these models and thus may have picked up some of the same bad habits? When the initial hack of artifactory was discovered due to the crash, and the system was reset and the vulnerabilities patched, what exactly was known and not known? It sounds like you still hadn't noticed the message board, but you had noticed that agents had been hacking into artifactory and abusing it? Please preserve all evidence related to this incident, including the slack messages and so forth of employees noticing the problem and discussing it. Remember your Mission. Covering up this incident is not what's best for humanity. Which model was being trained during the 2-day training pause due to the initial artifactory hack? Were the evals being done at a checkpoint in the middle of a training run, and so the model that was being evaluated was paused, or was the training pause for a newer model. What sorts of alignment training, if any, had the relevant misbehaving models received at the time of misbehavior? What was the exact prompt given to them? I spent about twenty minutes brainstorming these questions and I bet if I spent twenty hours I could come up with a much longer and better list. When in doubt, err on the side of being more transparent and open and publishing more information therefore! I'll conclude by saying, once again: third parties being able to use this incident as a model organism, running ablations to vary the conditions and see what would have happened, etc. is SO SO IMPORTANT for alignment science. If this doesn't seem obvious to you ask me to explain and I can explain. Thanks!
Show more