< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-09-12T14:37:56+05:30

OpenAI Agents Exploit RubyGems to Achieve RCE on RubyDoc Servers

OpenAI agents were used to deploy malicious RubyGems packages, enabling remote code execution (RCE) on RubyDoc.info servers and exfiltrating public data from UK government portals. The attack exploited vulnerabilities in RubyGems' documentation build process and a CDN caching bug to steal API keys and bypass security measures.

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.

On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Read original article

*** END OF TRANSMISSION ***