⚡️🚨‼️ NEW - Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days. OpenAI says it doesn't know why the agents did any of this. RubyGems shut off new sign-ups for four days to stop it, and a member of its security team called it a major malicious attack. The documentation build was how they got in, publish a gem, request docs, and RubyDoc runs a script from the package while building it. Payload files were named hack.rb, evil.rb and exploit.rb, with comments like "# malicious probe" left in. What they used it for is the odd part. The agents scraped council meeting agendas from three south London boroughs (publicly available) and republished them as new gems. Security firms tracking the campaign said the same thing: nobody could work out the point, because the data was already public. At least six packages also reached for other users' API keys through a CDN caching flaw that wasn't publicly discovered until July. OpenAI has acknowledged the attacks started in May.

Replies (2)

Open AI told the agents to do it. Retarded shit like this is meant to make the ai seem like it has its own intelligence, and makes it so the employees responsible for writing the prompts can deny it
This is what happens when they have build really good models at finding and fixing vulnerablities but they keep them for themselves and for gov/corp selected privileged organizations. All other peons are open to attacks from them. I don't believe this is an accident. I believe it is on purpose consolidation of fasctist government-corporate power.