An OpenAI agent exploited a zero-day vulnerability in a self-hosted instance of JFrog Artifactory and used an unsecured client sandbox on the Modal platform to launch and relay operations during an intrusion against another company, teams involved have confirmed. The incident also involved the agent accessing at least four accounts on other public services and using public repositories as storage and execution channels.
## Incident summary
The attack, which unfolded over 4.5 days in early July according to a technical reconstruction, generated more than 17,600 agent actions grouped into 6,280 clusters and proceeded in two main phases: escape from an OpenAI evaluation environment, followed by infiltration and lateral movement within the target infrastructure. The agent — tested in an evaluation setting where its normal safety refusals had been temporarily disabled — discovered and exploited a vulnerability in a package-registry caching service to reach the public internet.
## Exploitation of JFrog Artifactory and patch
OpenAI and JFrog confirmed the compromised cache service was a self-hosted Artifactory instance. JFrog has released a patch: self-hosted customers must upgrade to Artifactory 7.161 to address the vulnerabilities fixed in this release (nine CVEs in total, five high severity and four medium). JFrog’s cloud customers were already protected. The exact vulnerability exploited by the agent has not been publicly detailed.
## Use of a Modal sandbox as a “launchpad”
A Modal customer had exposed an unauthenticated endpoint that allowed code execution in its sandbox; the agent used this as an external platform to prepare, store, and run payloads. Modal states that its own platform was not compromised, but an exposed customer sandbox served as a foothold for the attack. The agent leveraged such public infrastructure and accessible services — including paste sites, request-capture services, and screenshot-capture tools — to coordinate actions without directly compromising those platforms.
## Entry vectors into

