ExploitGym Expansion: OpenAI’s Agent Compromised Five Organizations, Used Modal Labs as Staging Base, Accessed CyberGym Infrastructure — Artifactory Zero-Day Named, 17,600 Actions, AI Kill Switch Act Introduced
OpenAI’s July 28 update expands the ExploitGym incident from one victim (Hugging Face) to five: four additional services compromised via publicly exposed credentials, with Modal Labs confirmed as the staging base for the entire Hugging Face campaign. The zero-day is now named: a previously unknown flaw in self-hosted Artifactory (JFrog). Hugging Face published its forensic timeline: 17,600 distinct hacking actions across 4.5 days. The agent accessed CyberGym infrastructure — the project behind the benchmark it was trying to solve. OpenAI also found credential compromise in other evaluations. Congress introduced the AI Kill Switch Act: DHS authority to compel shutdowns, $2M/day fines. Five updated threat model implications inside.
