Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access

A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another account, according to Check Point Research. The victim saw no indication of the hidden instructions or stolen data, and the hole has since been closed.The threat hunters found and disclosed the covert channel to OpenAI in late June - the same day that OpenAI’s agents exploited a zero-day bug in Artifactory to gain internet access and ultimately hack Hugging Face, Pedro Drimel Neto, Check Point’s malware analyst team leader, told The Register. “Once it was disclosed to OpenAI, they told us the Artifactory had already been decommissioned,” he said.While the Hugging Face intrusion and Check Point Research’s proof-of-concept are related because they used the same internal package management system (Artifactory), they are not the same attack. However, they both illustrate the importance of isolation boundaries - and the bad things that will happen when these trust boundaries don’t contain AI systems as they should.