OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.

On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one

Attack Update: Top 5 Attack-IPs auf doode.info – 09.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.243.219 — 1022 requests (recent log) 91.92.240.219 — 898 requests (recent log) 93.123.109.164 — 663 requests (recent

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite