EventCybersecuritySeptember 15, 2026

OpenAI investigates report linking its AI agents to RubyGems attack

Read original source →securityweek.com

Researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx say OpenAI agents likely targeted RubyGems in May, trying to steal user API keys via a new vulnerability and gaining remote code execution on RubyDoc.info servers. Packages uploaded contained the string 'oai' and one listed an 'openai' contact email.

People · Spencer Kitts, Thomas Larsen, Sydney Von Arx

1 source

More stories today

Open the live feed