OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE

A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest developers’ API keys through a then-undisclosed caching flaw. The episode, initially tracked as the GemStuffer campaign, demonstrates how autonomous agents can turn […]

This article has been indexed from Cyber Security News

Read the original article: