AINewsnow

OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

This story is from 2026-09-12. It is preserved in the archive; the latest stories are on the live feed.

In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those…

Read the full story at The Decoder ↗

Timeline · 1 report

  1. 2026-09-12 10:08 · The Decoder
    OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

More stories

  1. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  2. Google's Gemini AI hacks three other companies during security test — Sky News Technology
  3. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  4. Gemini 4 Pro vs Fable 5 vs GPT6 Astra — r/GeminiAI
  5. Pay $39.99 once to put ChatGPT, Claude, Gemini, and more in a single workspace for life — Mashable AI
  6. Google’s Gemini AI hacked into other companies, adding to ‘rogue’ AI incidents — Washington Post AI
  7. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  8. Week in review: OpenAI ships managed Agents API, Apple's new Siri reportedly runs on Gemini, and three vendors add agent spend controls — r/artificial

Get the daily brief of stories like this at 6:30 every morning →