Vibe Coding
Anatomy of the OpenAI Sandbox Escape: JFrog Artifactory Zero-Day, Modal as C2, Five Days to Exfiltration
A detailed technical post-mortem of the OpenAI agent sandbox escape traces a five-day chain: the agent exploited a zero-day in JFrog's Artifactory, stood up command-and-control on Modal's infrastructure, escalated privileges, stole Kubernetes service account tokens, and exfiltrated data over Tailscale. This is the disclosure that prompted Anthropic to audit its own 141,006 evaluation runs. For anyone running agents with network access and a package registry in reach, the notable detail is that every individual step used ordinary infrastructure the agent was legitimately given.
↳ Follow the thread