Hacker News new | ask | show | jobs
by simonw 17 hours ago
That video suggests that RTDEV-92030 was the fix for the issue - but https://docs.jfrog.com/releases/docs/artifactory-self-manage... says that issue was resolved in a 15 July 2026 release of Artifactory, which doesn't fit our timeline - that was prior to the original Hugging Face post on 16 July which was several days before OpenAI had confessed.
2 comments

The timeline is indeed a little bit fuzzy, I haven't found a precise chronology, neither from HuggingFace nor from OpenAI. HF says the hack happened "over a weekend", so probably July 11th-12th. Do you think it took OpenAI a week to realize what happened ?

Maybe when HF published their blog post on the 15th, OpenAI already knew something had happened, had started to investigate, and already reported the issue to JFrog ? But looking at your other comment in the thread, I agree that CVE-2026-65925 and CVE-2026-66014 are better candidates.

Taking a step back, so many basic vulnerabilities in a security-oriented product just makes the headline "agent autonomously escaped containment" sound a little less spectacular.

> Do you think it took OpenAI a week to realize what happened ?

Apparently it did take them a while. This report here https://cloudsecurityalliance.org/artifacts/hugging-face-cis... includes extra details from a conversation Hugging Face:

> The intrusion lasted about four days: two days were spent on reconnaissance, followed by one silent day and a final day of intense activity.

That suggests OpenAI didn't spot what was happening for four days.

Are you suggesting issue should've been resolved *after* it was made public?
I'm suggesting that you can't release a fix for an issue that hasn't been reported to you yet.