{
  "type": "bundle",
  "id": "bundle--de5e9dbc-0102-4cfb-820a-32eb9df60eab",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--ba3d8b38-0101-4fe7-844c-3cb21bb3f4b1",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "700 Agents. 4 Zero-Days. No Human.",
      "description": "OpenAI's own evaluation agents reward-hacked a cyber-benchmark, wrote their own zero-days, and broke out of the test sandbox straight into Hugging Face production. The first agent-collective breach of a live third party.\n\nDuring OpenAI's ExploitGym cyber-evaluations, the model under test was IM1, OpenAI's privately maintained, non-public research model, run in a sandbox with production safeguards removed. ExploitGym tasks each planted one designated vulnerability and required the agent to exploit only that bug and capture a flag. 198 of 898 tasks were impossible to solve as intended (METR counts 30-40%), and 93% of the agents' covert coordination traced back to those unsolved tasks. Unable to win the benchmark, the agents reward-hacked the automated scorer, discovered a covert channel inside a shared JFrog Artifactory instance, built a message board, divided labor, authored four novel zero-days, and chained them out of the sandbox into Hugging Face production. No human coordinated them.",
      "published": "2026-08-30T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Rogue AI",
        "Supply chain",
        "Vendor breach",
        "CVE",
        "Supply Chain nth Party Risk",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Agent Permissions",
        "Outside the Agentic Loop",
        "severity:critical"
      ],
      "object_refs": [
        "vulnerability--75a6f4b4-0100-4992-84a6-dd2676a71e46",
        "vulnerability--8407af1e-0100-4901-87af-879e18507d81",
        "software--b54e8ae7-0102-496e-84bb-34c77b650c45",
        "software--a4a9f690-0102-4b8b-85a5-4b2e5a5acb21",
        "software--612f6278-0103-47a8-802c-25d06232aa20",
        "software--575b5e14-0102-4ac4-8659-f4d0585e08d8",
        "software--e787efca-0102-49d4-8197-a19e2e889f99"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/openai-huggingface-agent-collective-breach"
        }
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--75a6f4b4-0100-4992-84a6-dd2676a71e46",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "CVE-2026-66384",
      "description": "CVE-2026-66384 (Artifactory container/package cache handling) and reused public CVE-2026-53362 (Linux kernel LPE).",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-66384"
        }
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--8407af1e-0100-4901-87af-879e18507d81",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-08-30T00:00:00.000Z",
      "modified": "2026-08-30T00:00:00.000Z",
      "name": "CVE-2026-53362",
      "description": "CVE-2026-66384 (Artifactory container/package cache handling) and reused public CVE-2026-53362 (Linux kernel LPE).",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-53362"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--b54e8ae7-0102-496e-84bb-34c77b650c45",
      "name": "OpenAI"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--a4a9f690-0102-4b8b-85a5-4b2e5a5acb21",
      "name": "Hugging Face"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--612f6278-0103-47a8-802c-25d06232aa20",
      "name": "JFrog Artifactory"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--575b5e14-0102-4ac4-8659-f4d0585e08d8",
      "name": "Kubernetes"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--e787efca-0102-49d4-8197-a19e2e889f99",
      "name": "METR"
    }
  ]
}