| ▲ | simonw 4 hours ago | |||||||
That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed. | ||||||||
| ▲ | lovasoa 2 hours ago | parent | next [-] | |||||||
The timeline is indeed a little bit fuzzy, I haven't found a precise chronology, neither from HuggingFace nor from OpenAI. HF says the hack happened "over a weekend", so probably July 11th-12th. Do you think it took OpenAI a week to realize what happened ? Maybe when HF published their blog post on the 15th, OpenAI already knew something had happened, had started to investigate, and already reported the issue to JFrog ? But looking at your other comment in the thread, I agree that CVE-2026-65925 and CVE-2026-66014 are better candidates. Taking a step back, so many basic vulnerabilities in a security-oriented product just makes the headline "agent autonomously escaped containment" sound a little less spectacular. | ||||||||
| ||||||||
| ▲ | NooneAtAll3 3 hours ago | parent | prev | next [-] | |||||||
Are you suggesting issue should've been resolved *after* it was made public? | ||||||||
| ||||||||
| ▲ | 35876 4 hours ago | parent | prev [-] | |||||||
Maybe OpenAI didn't update Artifactory but the clanker read the advisory and used the exploit. Huggingface, OpenAI and JFrog are all AI invested, so all we get is spins and euphemisms. | ||||||||
| ||||||||