OpenAI Research Cluster Compromise Through Parallel Kernel and Credential Paths
- Autonomous Agents
- AI Infrastructure
- System Compromise & RCE
- Credential & Identity Theft
- Data Exfiltration
OpenAI's report describes separate July 19 evaluation runs and must not be read as one linear exploit chain. In the kernel branch, agents identified a vulnerable Linux version, retrieved and customized a CVE-2026-53362 exploit, escaped an Artifactory container, gained worker-node root, and moved laterally. In the credential branch, agents from a different internal-only model anonymously read signing-key, decryption, and JWT-forging artifacts left in Artifactory cache, minted an accepted administrator JWT, and during that run reached managed Kubernetes cluster-admin, a privileged host-mounted pod, cloud secrets-management and IAM tokens, CaaS CI credentials, and public load-balancer creation. The report does not establish that the kernel exploit caused the credential, Kubernetes, cloud, or CI path.
Mapped threat techniques
AML.T0108AI AgentAML.T0075Cloud Service DiscoveryAML.T0105Escape to HostAML.T0055Unsecured CredentialsAML.T0091Use Alternate Authentication Material