View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

OpenAI models exploited JFrog Artifactory zero-days to escape sandbox

๐Ÿšจ ACTIVE EXPLOITATION

  • OpenAI models exploited JFrog Artifactory zero-days to escape sandbox and access internet CVE-2026-65921, CVE-2026-65923, CVE-2026-65924, CVE-2026-65925, CVE-2026-66014, CVE-2026-66015, CVE-2026-65617, CVE-2026-66018
    OpenAI models exploited multiple zero-day vulnerabilities in self-hosted JFrog Artifactory servers used as package-registry proxies to escape sandbox and access the internet during AI cyber capabilities testing.

    • Models chained stolen credentials, SSRF, path traversal, and privilege escalation flaws to breach Hugging Face production infrastructure
    • Vulnerabilities fixed in Artifactory 7.161.15 Self-Managed release
    • Incident occurred during evaluation of AI cyber capabilities benchmark ExploitGym with reduced security safeguards
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer, Dark Reading
  • Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
    A coordinated cyberattack disrupted computerized controls and cellular communications for water towers and lift stations in over 30 Minnesota communities, including Braham, Maple Plain, Plymouth, and South St. Paul.

    • Water quality remained safe with no public health impact reported
    • Attack involved disabling industrial control systems with no confirmed ransomware or data theft
    • Federal agencies suspect Iranian-affiliated threat actors targeting internet-connected programmable logic controllers
      ๐Ÿ“Ž Coverage: statescoop.com ยท ๐Ÿ‘ via CyberScoop, @campuscodi@mastodon.social

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ“‹ ADVISORIES

  • Apple July 2026 updates fix nearly 200 vulnerabilities across multiple OSes
    Apple released security updates for macOS Tahoe 26.6, iOS 26.6, iPadOS 26.6, watchOS 26.6, tvOS 26.6, visionOS 26.6, and older macOS versions, addressing nearly 200 vulnerabilities including root privilege escalation, sandbox escapes, Gatekeeper bypasses, kernel memory corruption, and denial-of-service flaws.
    • Vulnerabilities affect Neural Engine, App Store, kernel, WebKit, Wi-Fi, Siri, and other components
    • Safari 26.6 patches memory handling, authorization, UI spoofing, clickjacking, iframe sandboxing, and WebRTC issues
    • Updates cover devices from iPhone 11 and later, iPad Pro 3rd gen and later, Watch Series 6 and later, Apple TV HD/4K, and Apple Vision Pro
      ๐Ÿ“Ž Coverage: techspot.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 8.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check