OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

Researchers at Check Point discovered a covert data-stealing channel within OpenAI's internal JFrog Artifactory instance. The vulnerability allowed for cross-account task execution, highlighting critical security risks in AI infrastructure.
Why it matters
This incident underscores the growing security challenges associated with AI systems and the necessity for robust isolation boundaries in enterprise software environments.
Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access
A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another account, according to Check Point Research. The victim saw no indication of the hidden instructions or stolen data, and the hole has since been closed.
The threat hunters found and disclosed the covert channel to OpenAI in late June - the same day that OpenAI’s agents exploited a zero-day bug in Artifactory to gain internet access and ultimately hack Hugging Face , Pedro Drimel Neto, Check Point’s malware analyst team leader, told The Register. “Once it was disclosed to OpenAI, they told us the Artifactory had already been decommissioned,” he said.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in