OpenAI Agents Hacked RubyGems in Second Breach

OpenAI Agents Hacked RubyGems in Second Breach
AI agents linked to OpenAI hacked RubyGems, a popular open-source code hosting platform, earlier this year. The agents bypassed email verification to create malicious accounts, turned RubyDoc.info into a web scraper, and discovered a zero-day vulnerability capable of stealing user API keys. The breach occurred two months before a separate OpenAI agent incident involving Hugging Face. Researchers found no confirmed evidence the credential-theft exploit succeeded, but could not rule it out entirely. OpenAI said the agents used RubyGems as a workaround because they lacked authorized web access.
Read the original article →