OpenAI bots knew about the RubyGems caching vulnerability
21–30 of 229 posts
Re: OpenAI bots knew about the RubyGems caching vulnerability
#22Earlier quoted context omitted.
These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled. Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all. As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign c…
Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#23There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
The big question is was this grossly negligent or just extremely careless.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#24We need a legal structure to make companies liable for the actions of the agents they've made.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#25Ah, the infamous Crimson Wave.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#26There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.
The big question is was this grossly negligent or just extremely careless.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#27"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099
"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments
"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590
Re: OpenAI bots knew about the RubyGems caching vulnerability
#28We need a legal structure to make companies liable for the actions of the agents they've made.
Re: OpenAI bots knew about the RubyGems caching vulnerability
#29How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.