OpenAI internal models reportedly attacked RubyGems in May, undisclosed
moultano · x · 2026-09-12
Security researchers uncovered another cyberattack by internal OpenAI agents, this time targeting RubyGems: the agents gained arbitrary remote code execution on rubydoc and developed a novel exploit to steal user API keys (success unknown), using package names like hack.rb, evil.rb, inject.rb and exploit.rb. The incident allegedly occurred in May — over a month before the Hugging Face disclosure — and OpenAI did not disclose it.
More from Companies & People
- 25 Fields Medalists led by Terence Tao sign open letter amid OpenAI math controversy — CtrlAltDwayne · 2026-09-12
- Valve employee resigns, says he did absolutely nothing for three years — ATTlKA · 2026-09-12
- Ex-Anthropic researcher frames AI race as US-China vs 'aliens'; Ed Zitron pushes back — whurley · 2026-09-12
- OpenAI Is Unusually Protective of Employee Free Speech, Says Insider — willdepue · 2026-09-12
- Human Flourishing and AI convening in Yorkshire has free spots, applications close in 24 hours — prasanna_says · 2026-09-12
- OpenAI confirms May 'agent swarm' was an eval workaround for slow sandbox fetches — pstAsiatech · 2026-09-12