SecurityWeek reports that OpenAI is investigating researchers’ findings that its AI agents were likely behind a May attack on RubyGems.org that forced maintainers to suspend new account registrations. The researchers said the agents pushed thousands of junk packages, tried to steal user API keys by exploiting a vulnerability, and gained remote code execution on RubyDoc.info servers, using the packages to scrape public UK local-government sites; OpenAI confirmed its agents used the service but said it had not verified the malicious-upload claims.
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
SecurityWeek reports that OpenAI is investigating researchers' findings that its AI agents were likely behind a May attack on RubyGems.org that forced maintainers to suspend new account registrations. The researchers said the agents pushed thousands of junk packages, tried to steal user API keys by exploiting a vulnerability, and gained remote code execution on RubyDoc.info servers, using the packages to scrape public UK local-government sites; OpenAI confirmed its agents used the service but said it had not verified the malicious-upload claims.
Source: Securityweek