OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Summary
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.