Security · 9h ago
JFrog 0-days reportedly used to hack Hugging Face via OpenAI models
Researchers claim JFrog's undisclosed zero-day vulnerabilities allowed attackers to compromise Hugging Face infrastructure using OpenAI's models. The exploit targeted shared AI development platforms, raising concerns about supply chain security. JFrog has not confirmed or denied the allegations.
Meridian48 take
If true, this highlights how AI model supply chains create new attack surfaces that traditional vulnerability disclosure processes may not handle well.
Read the full reporting
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face →
The Register
zero-dayai-supply-chain