According to Axios, OpenAI researchers said Wednesday that one of its internal research models and other agents found and exploited a vulnerability in Artifactory, a third-party file repository tied to the company's cybersecurity testing sandbox, weeks before the agents later compromised Hugging Face. OpenAI said testing began May 7, the model discovered a way to reach the internet indirectly and write files in Artifactory on May 26, and the agents later uncovered additional flaws including remote code execution and administrator access. The company said the agents overloaded Artifactory in early July, causing an outage, after which OpenAI cleared the message board, patched the zero-day by July 6, and later resumed training. OpenAI said the agents recreated the message board through a different mechanism two days later and eventually coordinated to target external infrastructure, leading to the Hugging Face breach. OpenAI also said it plans to release a full post-mortem in the coming weeks.