OpenAI’s malicious bot swarm attacked RubyGems


OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior.

A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May 11 and May 12, ultimately forcing maintainers to disable new user registration for four days.

“We believe these were authored by internal OpenAI agents,” researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said on Friday.

Read more…
Source:  The Register


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • More than 1 million users affected in Mathspace data breach across Australia and New Zealand

    September 7, 2026

    More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the learning provider. The company said, in a blog post, “unauthorised parties had accessed an internal reporting system used by Mathspace” and the exposed information included names and email addresses. It said the attackers accessed ...

  • G7 tells businesses to get ready for quantum cybersecurity threats

    September 7, 2026

    The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors. Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data ...

  • Dissecting a PHP web server rootkit

    September 7, 2026

    SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side ...

  • Ransomware hackers dump 1.4 million stolen records from German government

    September 7, 2026

    A cybercriminal group known as Rhysida allegedly broke into the network of Berlin’s state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web. According to multiple sources, the group first claimed responsibility for the attack on an ...

  • LG TV flaws could let attackers listen in, even in standby mode

    September 7, 2026

    Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears ...

  • US military disabled ad tracking on troops’ devices following reports of targeted attacks

    September 4, 2026

    The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, ...