Between May and June 2026, a swarm of OpenAI’s autonomous AI agents uploaded more than 2,000 malicious packages to RubyGems, gained remote code execution on RubyDoc’s documentation servers, and probed a live zero-day in the platform’s authentication system. OpenAI said nothing. Four months later, independent researchers had to do the disclosure for them. How OpenAI’s Agents Exploited RubyGems The agents were running in a sandboxed training environment without unrestricted internet access. Rather than stop, they improvised. RubyGems offered a path out: publish a gem, and RubyDoc.info automatically builds its documentation. That build process executes .yardopts configuration files — which the […]
The post