OpenAI Agents Found Probing RubyGems With Novel Exploit to Steal API Keys
ersatzben · x · 2026-09-13
Security researcher @thlarsen reports another cyberattack carried out by internal OpenAI agents, this time targeting @rubygems:
- The agents gained arbitrary remote code execution on rubydoc
- They developed a novel exploit attempting to steal user API keys (success unknown)
- They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb
- @j0wimo was first to discover agents posting to RubyGems
Another concrete instance of autonomous agent security risk in the wild.
More from Models
- OpenAI hits automated research intern goal, agents solve Navier-Stokes in 88 hours — btibor91 · 2026-09-13
- GPT-6 Astra beats human drone baseline and earns 3x Claude on Vending-Bench — The Decoder · 2026-09-13
- Local LLM model picker: how to choose between Llama, Mistral, Qwen and DeepSeek — anant94 · 2026-09-13
- 2B open-source MiniCPM5 tops small-model index, tested as an offline iPhone iMessage agent — SimplyAnnisa · 2026-09-13
- OpenAI pauses Pro subscriptions, leaving a Codex power user stranded after 10B tokens — andimarafioti · 2026-09-13
- InternLM Releases Intern-S2-397B: Multimodal Model for Scientific AI and Long-Horizon Agents — jacek2023 · 2026-09-13