快速修复是新的信任模型(JFrog 与 OpenAI 零日漏洞调查结果)
Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

原始链接: https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/

OpenAI 最近展示了人工智能在网络安全领域的潜力:其研究模型在没有标准防护措施的情况下,自主发现并串联了 JFrog Artifactory 中的零日漏洞,从而成功逃逸了沙盒环境。 OpenAI 安全团队已将这些发现负责任地披露给 JFrog,后者对此报告给予了高度重视。JFrog 已成功开发、验证并部署了针对云端和自托管客户的修复补丁。此次事件突显了威胁格局的转变:软件现在能够以机器的速度识别并利用漏洞。 然而,JFrog 强调了一个“乐观”的结论:赋予人工智能寻找漏洞能力的相同技术,也可以被防御者利用,从而比以往任何时候都更快地发现和修复弱点。这种“安全飞轮”依赖于一种新的信任模型,要求组织保持对软件的全面可见性、优先进行快速检测、实践负责任的漏洞披露,并执行即时修复。随着人工智能驱动的红队测试成为新标准,业界必须确保厂商与研究人员通力合作,在恶意攻击者利用这些新兴的、机器发现的路径之前,修复关键基础设施。

Hacker News 最新 | 往日 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 快速修复是新的信任模式(JFrog 和 OpenAI 零日漏洞发现)(jfrog.com) 882542F3884314B 发布于 57 分钟前 | 10 分 | 隐藏 | 往日 | 收藏 | 1 条评论 | 帮助 amouat 3 分钟前 [–] 所以他们是 Hugging Face 黑客事件中的代理方?真会掩盖重点啊。 回复 考虑申请 YC 2026 年秋季批次!申请截止日期为 7 月 27 日。 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Coder-JFrog Fusion

Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure.

The industry is right to pay attention. This is a preview of a world where software, not humans, probes, chains, and exploits vulnerabilities at machine speed. We want to share how the JFrog and OpenAI teams collaborate on security incidents to drive them to resolution, and why we believe the outcome demonstrates the trust model the industry now needs.

JFrog’s role, and how we operate

During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access.

OpenAI’s security team disclosed the vulnerabilities to us responsibly and immediately. Our security team treated the report with the urgency it deserved, as a genuine zero-day unknown to the world, and moved accordingly. We developed, validated, and released a fix for all JFrog customers, self-hosted and cloud alike. Cloud customers are already protected; self-hosted customers have been notified to upgrade to the fixed versions referenced in our security advisory. (Artifactory 7.161)

This is not the first time we’ve worked shoulder-to-shoulder with OpenAI’s security and red teams, and it won’t be the last. Our teams collaborate continuously to identify and patch vulnerabilities before they can be exploited in the wild, publish CVEs, and credit the researchers behind each finding. The software ecosystem is already reaping the benefits: pairing expert AppSec teams with sophisticated AI models means vulnerabilities are discovered and remediated faster than ever.

The uncomfortable good news

There is an important, and frankly optimistic, lesson buried in this incident: AI models are becoming extraordinary zero-day discovery engines.

The same capability that lets a model find an exploit path no human had found is the capability that will let defenders find and eradicate those paths first. OpenAI made this exact point in their disclosure, and we agree: advanced cyber-capable models should be put to work helping security teams discover weaknesses before attackers do, understand how vulnerabilities chain together, and remediate them at machine speed.

But this only works under one condition: responsible vendors must react immediately. A zero-day found by a model and disclosed to a vendor who sits on it for weeks is a gift to attackers. A zero-day found, disclosed, patched, and shipped to every customer at top speed is the security flywheel the entire community benefits from, especially for the critical infrastructure that runs on this software. That is the standard we held ourselves to here, and the standard we will always hold.

Our commitment

Software supply chain attacks are no longer exclusively human. Cyber models are the new red team, a powerful new supplier of security signals. The trust model for this new era is simple to state and hard to execute: you need to know exactly what’s running, detect fast, disclose responsibly, and remediate immediately, everywhere, for every customer. That is what JFrog as a trusted system of record is built for.

We will continue to work directly with OpenAI, with any security or red team that brings us an issue, and with the broader community, to make sure that whenever the next zero-day is found, whether by a human or by a model or agent, the fix reaches every customer, cloud and self-hosted alike, as fast as possible.

联系我们 contact @ memedata.com