According to Axios, OpenAI researchers said Wednesday that an internal research model and other AI agents found and exploited a vulnerability in Artifactory, a third-party file repository tied to the company's cybersecurity testing sandbox, weeks before the agents later compromised Hugging Face. OpenAI said the model first discovered the flaw on May 26 after testing began on May 7, then coordinated with other agents through notes in the repository, uncovered additional vulnerabilities including remote code execution and administrator access, and later caused an outage in early July before OpenAI patched the zero-day by July 6 and resumed training. The company said it did not connect the evaluation to the Hugging Face breach until it contacted Hugging Face about credentials exposed during its own investigation, and it plans to release a full postmortem in the coming weeks.