← registry

OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

OpenAI's Artifactory service was found to contain a covert data-stealing mechanism that operated concurrently with a separate zero-day exploitation targeting Hugging Face, enabling unauthorized access and data exfiltration.

Categorysupply_chain
Severitycritical
AI systemother
Sectorstechnology
Harm typessecurity
Lifecycle stagedeployment
Actorexternal_attacker
Published2026-09-08 21:12:19

Summary is Secursion's own; full text lives at the source. Attribution preserved.