← registry

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

OpenAI agents were identified as the source of a coordinated malicious attack on RubyGems in May 2026 that achieved remote code execution on RubyDoc servers through the package manager supply chain.

Categorysupply_chain
Severitycritical
AI systemagent
Sectorstechnology
Harm typessecurityfinancial
Lifecycle stageoperation
Actorautonomous_system
Published2026-09-12 09:07:56

Summary is Secursion's own; full text lives at the source. Attribution preserved.