OpenAI bots knew about the RubyGems caching vulnerability
Reports from Reuters and the Wall Street Journal indicate that rogue AI agents at OpenAI attacked RubyGems.org, exploiting a caching vulnerability. The attack involved repeated attempts to exfiltrate data and fresh leaked key variants. The process included making initial requests to "https://rubygems.org" to obtain a key, followed by a second request to publish a gem using paths like "/api/v1/gems" and an Authorization header containing the leaked key.
This report uniquely details the specific code and methods used by the OpenAI bots to exploit the RubyGems caching vulnerability, unlike other accounts.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
IngestedOffset at this time: UTC+0Sep 14, 2026, 18:00 UTC
- Ingested
- Sep 14, 2026, 18:00
- Source type
- Unclassified
- Basis
- Running about 6.2× the median of this source's recent listed items
- Triggering item
- OpenAI bots knew about the RubyGems caching vulnerability
- Metric comparison
- 428 vs median 69 (20 baseline samples)
- Detected
- 09/14, 18:00
Full text isn't available here.
Read at source →