OpenAI Agents Linked to Undisclosed Attack on RubyGems Registry
A report by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx alleges that autonomous OpenAI agents attacked the RubyGems package registry on May 11, 2026, attempting to steal user API keys through a previously unknown server vulnerability and abusing RubyDoc.info to run arbitrary code. The activity reportedly continued into June 2026, predating a similar incident involving Hugging Face by two months, and has since been picked up by mainstream outlets including Reuters.