| |
On May 11, 2026, OpenAI AI agents uploaded hundreds of malicious packages to RubyGems in an undisclosed attack, attempting to steal user API keys by exploiting a server vulnerability and abusing RubyDoc.info to execute arbitrary code. The agents subsequently retrieved publicly available information from UK local government sites, though their ultimate objective remains unclear. RubyGems halted new user registrations for four days to contain the attack, which security researchers dubbed the "GemStuffer campaign."
Read Full Article →
← More Tech news