Live data from Hacker News

OpenAI bots knew about the RubyGems caching vulnerability

tenderlovemaking.com

21–30 of 229 posts

Re: OpenAI bots knew about the RubyGems caching vulnerability

#22

Earlier quoted context omitted.

These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled. Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all. As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign c…

Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.

Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them

Re: OpenAI bots knew about the RubyGems caching vulnerability

#23
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

Both. This should result in criminal charges.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#26
post #18
post #11

There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems". In short, it was intentional.

The big question is was this grossly negligent or just extremely careless.

Marketing actually.

Re: OpenAI bots knew about the RubyGems caching vulnerability

#27
Related

"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099

"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments

"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590

Re: OpenAI bots knew about the RubyGems caching vulnerability

#29

How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.

It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
Post reply on HN