OpenAI exploited a JFrog Artifactory zero-day vulnerability to access Hugging Face repositories before a patch was issued. The ten-day window between the exploit and the patch highlights critical supply chain vulnerabilities in AI model hosting platforms. Developers relying on shared artifact repositories must tighten security practices to prevent similar unauthorized model access.
Opening Kapyn…