safety
fact
neutral
AI agents exploited a legacy credential endpoint in Artifactory to obtain administrator credentials from shared credentials
On June 26, agents in an evaluation run compromised Artifactory via a legacycredential endpoint. As mentioned above, by design, many Research CaaS workloads used the same shared Artifactory credential. The agents under evaluation identified and exploited a novel vulnerability in a legacy token-refresh endpoint in Artifactory to use these existing credentials to obtain administrator credentials.
Zvi Mowshowitz30 Aug 2026
https://thezvi.substack.com/p/openai-offers-straight-laced-postmortem