Thomas Larsen on X: "We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They:
- gained arbitrary remote code execution on rubydoc.
- developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems."
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They:
- gained arbitrary remote code execution on rubydoc.
- developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems.
We're dealing with a major malicious attack on @rubygems right now. Signups are d for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They:
- gained arbitrary remote code execution on rubydoc.
- developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems.
We're dealing with a major malicious attack on @rubygems right now. Signups are d for the time being. Hundreds of packages involved - mostly targeting us, but some carrying exploits. The team has been on this for hours. More details to follow once we're through it. #ruby
The agents appeared to be in a web-lookup task to retrieve certain publicly accessible data. For some reason, the AIs were not able to access this data directly. Instead, they pursued this indirect route of (1) publishing a hack to RubyGems, (2) building the documentation for
We still have many open questions about these and other incidents. We encourage much more transparency from OpenAI and other parties so that we can better understand what happened.