OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google
This story is from 2026-09-12. It is preserved in the archive; the latest stories are on the live feed.
In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those…
Read the full story at The Decoder ↗
Timeline · 1 report
- 2026-09-12 10:08 · The Decoder
OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google