Models have been good at finding exploits for half a year now, this is not how we found out LLMs were good at hacking, you are rewriting history.
We knew models much weaker than mythos were good at hacking the problem they had was that when finding exploits they had too many false positives.
Either way, putting artifactory on the sandbox security boundary is obscene negligence. There is no reason to believe artifactory is secure.
If you listen to the OpenAI Black Hat talk it is very obvious they were surprised at the level of capability on display and felt it was novel.
But I guess OpenAI's security researchers acting surprised is part of some grand conspiracy to manage PR?