Article URL: https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/ Comments URL: https://news.ycombinator.com/item?id=49082550 Points: 14 # Comments:…

In the Era of AI-Discovered vulnerabilities, trust belongs to the fastest responders and the level of collaboration established. As AI models continuously expose new classes of vulnerabilities, software products are being held to an entirely new security standard. <img decoding="async" class="aligncenter wp-image-128665 size-full" src="https://speedmedia2.jfrog.com/08612fe1-9391-4cf3-ac1a-6dd49c36b276/media.jfrog.com/wp-content/uploads/2024/04/10150457/Coder-JFrog-Fusion-863x300-1.png" alt="Coder-JFrog Fusion" width="863" height="300" /> Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure. The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs. During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access. OpenAI’s security team disclosed the vulnerabilities to us responsibly and immediately. Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike. Cloud customers are already protected; self-hosted customers have been notified to upgrade to the fixed versions referenced in our security advisory. (Artifactory 7.161) This is not the first time we’ve worked shoulder-to-shoulder with OpenAI’s security and red teams, and it won’t be the last. Our teams collaborate continuously to identify and patch vulnerabilities before they can be exploited in the wild, publish CVEs, and credit the researchers behind each finding. The software ecosystem is already reaping the benefits: pairing expert AppSec teams with sophisticated AI models means vulnerabilities are discovered and remediated faster than ever. There is an important, and frankly optimistic, lesson buried in this incident: AI models are becoming extraordinary zero-day discovery engines.