Maybe OpenAI didn't update Artifactory but the clanker read the advisory and used the exploit.
Huggingface, OpenAI and JFrog are all AI invested, so all we get is spins and euphemisms.
This seems unlikely as it would mean JFrog knew the vulnerability before OpenAI, which this blog posts clearly says the opposite
This seems unlikely as it would mean JFrog knew the vulnerability before OpenAI, which this blog posts clearly says the opposite