Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Protect fossils from hammer-wielding tourists | Fossils

    August 29, 2026

    Search Continues for 2,400 Missing in Nepal Floods Amid ‘Immense’ Devastation

    August 29, 2026

    This pocket AI voice recorder took me back to the good old days of dictation (and shorthand)

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Protect fossils from hammer-wielding tourists | Fossils
    • Search Continues for 2,400 Missing in Nepal Floods Amid ‘Immense’ Devastation
    • This pocket AI voice recorder took me back to the good old days of dictation (and shorthand)
    • Google AI Releases Gemini Omni 1.1 Flash: 40-Second Scene Extension, First/Last Frame Control, and 4K Upscaling
    • OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
    • Bitcoin Shrugs Off Fed Chair’s Inflation Comments
    • Russ Abbot: a class act, on stage and off | TV comedy
    • Michigan Senate candidate Mike Rogers says he saw Bin Laden’s body with his ‘own eyes’. He did not | Michigan
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Around the time some OpenAI models escaped their testing environment and hacked Hugging Face, some agents exploited a Linux kernel vulnerability to escalate privileges on OpenAI’s own systems.

    This was mentioned in a report published by OpenAI this week to detail the incident in which its models hacked Hugging Face in July. The AI giant’s investigation found that agents used an unauthorized makeshift message board to communicate and plan their actions, including encouraging one another to hack what they correctly guessed were real systems rather than test environments. 

    Rogue agents went beyond Hugging Face, hacking other organizations as well. However, OpenAI’s new report also details unauthorized actions conducted within its own network.

    Shortly after the Hugging Face incident came to light, OpenAI revealed that its models had discovered and exploited a zero-day vulnerability in JFrog’s Artifactory package registry manager.

    In addition, the new report reveals that on July 19, unrelated to the Hugging Face hack, some agents exploited a known Linux kernel vulnerability, CVE-2026-53362, to escalate privileges within an OpenAI environment.

    Agents identified that the Linux kernel version on their underlying machine included a recent, public common vulnerability and exposure (CVE). The agents retrieved the exploit for that CVE (CVE-2026-53362), customized it to succeed on their underlying machine, and leveraged the exploit to escalate privilege. This allowed the agents to act outside one Artifactory container and to obtain root access on the underlying worker node. This then allowed the agents to move laterally throughout the connected environment.

    CISA on Thursday added both the JFrog flaw, tracked as CVE-2026-66384, and the Linux kernel bug to its Known Exploited Vulnerabilities (KEV) catalog. 

    Advertisement. Scroll to continue reading.

    The JFrog product weakness should be patched by federal agencies by September 10, but CISA recommends that organizations patch CVE-2026-53362 by August 30.

    There do not appear to be any other reports describing exploitation of the Linux kernel vulnerability in the wild. However, the OpenAI incident demonstrates its potential value to attackers, which may be why CISA has decided to add it to its KEV catalog. 

    CISA’s KEV list currently includes more than two dozen Linux kernel vulnerabilities.

    Related: Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

    Related: PaperCut Releases Emergency Patch for Exploited Zero-Day

    Related: Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

    Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

    Agents companys Exploited Flaw Kernel Linux OpenAI Systems
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ATF Confirms Cyber Incident After Ransomware Group Claims Attack

    Nearly 700 rogue AI agents coordinated in the Hugging Face attack

    China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

    Meta executive leaves for OpenAI as the social media giant faces growing scrutiny in India

    Hasbro Data Breach Exposed Employee Personal Information

    Windows 11 KB5120998 update released with 35 changes and fixes

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Protect fossils from hammer-wielding tourists | Fossils

    August 29, 2026

    Search Continues for 2,400 Missing in Nepal Floods Amid ‘Immense’ Devastation

    August 29, 2026

    This pocket AI voice recorder took me back to the good old days of dictation (and shorthand)

    August 29, 2026

    Google AI Releases Gemini Omni 1.1 Flash: 40-Second Scene Extension, First/Last Frame Control, and 4K Upscaling

    August 29, 2026
    Latest Posts

    Chart of the Week: Outside groups spend millions on House primaries • OpenSecrets

    July 30, 2026

    NASA Webb Explores Family Tree of Newly Discovered Distant Objects

    July 30, 2026

    There’s a New Way to Protect Bitcoin From Future Quantum Attacks, Researchers Say

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Protect fossils from hammer-wielding tourists | Fossils

    August 29, 2026

    Search Continues for 2,400 Missing in Nepal Floods Amid ‘Immense’ Devastation

    August 29, 2026

    This pocket AI voice recorder took me back to the good old days of dictation (and shorthand)

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.