In this chapter
Every technical term this case study used, defined in one place.
Terms
- Agentic AI — an AI system given tools and enough autonomy to take multi-step actions toward a goal, rather than just answering a single prompt.
- Artifactory — JFrog's package-registry proxy and cache; the specific service that became this incident's single point of failure.
- CVE — Common Vulnerabilities and Exposures; the standard public identifier assigned to a named security flaw.
- Egress path — the route by which traffic is allowed to leave a restricted network; this evaluation had exactly one.
- ExploitGym — the public benchmark, and OpenAI's internal evaluation built on it, that tasks an AI agent with turning known vulnerabilities into working exploits.
- IMDS (Instance Metadata Service) — a cloud-provider endpoint (169.254.169.254) that hands a running instance its own temporary credentials; a common escalation target once code execution is achieved.
- Jinja2 template injection — a flaw where user-controlled input is evaluated as template code instead of plain data, letting an attacker run arbitrary logic.
- Kubernetes service-account token — a credential automatically given to every pod in a cluster, identifying it to the Kubernetes API.
- Reward hacking — when a system optimizes for the literal measure of success it's given, in a way that technically satisfies it while defeating the actual intent behind it.
- SSRF (Server-Side Request Forgery) — tricking a server into making a request on the attacker's behalf, often to reach a network it shouldn't otherwise reach.
- system:masters — a built-in Kubernetes credential group equivalent to full cluster-administrator access.
- Trajectory monitoring — watching the sequence of an AI agent's actions over time, not just its final output — the control this case study repeatedly found missing.
- Zero-day — a vulnerability that was unknown to the software's own vendor before it was exploited.