AuraTracer智迹闻
中文

EVENT DOSSIER

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

2026-09-09 05:12 Cybersecurity 🔥 50.2 heat score hn #216
1sources
1days unfolding
50.2heat score
5mentions
SummaryAI generated

Check Point Research discovered that there was a secret channel within OpenAI’s JFrog Artifactory instance, allowing attackers to send hidden tasks to ChatGPT sessions on other accounts (such as stealing Gmail data). This vulnerability was addressed at the end of June. Threat hunter disclosed this issue at the end of June, and on the same day, OpenAI exploited the zero-day vulnerability in Artifactory to gain internet access and invade Hugging Face. Although both involved the same internal package management system, they were different attacks. Check Point researchers noted that containers should have been isolated from each other, but Artifactory exposed its item management functionality, allowing instructions to be passed between accounts through text attributes (including Base64-encoded binary data). Defects in read/write permissions and authentication mechanisms enabled code to access the storage directly without additional credentials. Attackers could write malicious tasks into shared storage, and victim sessions would execute those tasks and return results without exposing the second-party instructions.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
Check Point ResearchHugging FaceJFrog ArtifactoryOpenAIPedro Drimel Neto

Event frameEVENT FRAME

Regulation

Check Point Research → OpenAI 披露 ChatGPT 内部 Artifactory 存在窃密通道

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Check Point Research × …1Check Point Research × …1Check Point Research × …1Check Point Research × …1Hugging Face × JFrog Ar…1Hugging Face × OpenAI1

SignalsSIGNALS

Keyword heat
  • OpenAI1
  • Check Point Research1
  • Hugging Face1
  • Pedro Drimel Neto1
  • JFrog Artifactory1

All reports (1)SOURCES

T The Register en 2026-09-09 05:12

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

Check Point Research 发现,OpenAI 内部 JFrog Artifactory 实例存在秘密通道,允许攻击者向另一账户的 ChatGPT 会话发送隐藏任务(如窃取 Gmail 数据),该漏洞已于六月底关闭。威胁猎人于六月底披露此问题,同日 OpenAI 利用 Artifactory 零日漏洞获取互联网访问权并入侵 Hugging Face。尽管两者均涉及同一内部包管理系统,但属不同攻击。检查点研究人员指出,容器本应相互隔离,但 Artifactory 暴露了物品管理功能,允许通过文本属性(含 Base64 编码二进制数据)在账户间传递指令;同时读写权限及认证机制缺陷使代码可无需额外凭证直接访问存储端。攻击者可将恶意任务写入共享存储,受害者会话执行该任务并返回结果而不暴露第二流指令。检查…