And in OpenAI's case to ask the model to try to find vulnerabilities and breakout before running training in the environment.
Fast remediation would be the new standard to outside vulnerability reports, but also a follow up to determine how you can adapt the approach of the reporter to find vulnerabilities preemptively.
https://www.cve.org/CVERecord?id=CVE-2026-66014 (reported by Amy Burnett, OpenAI) looks suspicious:
> JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
Also https://www.cve.org/CVERecord?id=CVE-2026-65925 (reported by Matthew Bryant, OpenAI):
> A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.
However, many questions remain. JFrog positions itself as a vibe coding and AI security (!) company:
https://cybersecurityasia.net/jfrog-nvidia-secure-agentic-ai...
JFrog's own vibe code scanner failed:
https://jfrog.com/blog/jfrog-introduces-ai-generated-code-va...
Given the feature explosion and chaos in the Artifactory cache, it is likely vibe coded and hence full of primitive security vulnerabilities.
JFrog is spinning this as an AI victory together with OpenAI. To the contrary, it is a hype and vibe coding failure.
But the AI bloggers will omit the vulnerability generation part.
amouat•55m ago
Way to bury that lede.