OpenAI Agents Attacked RubyGems Before Hugging Face Breach, Raising AI Security Concerns
OpenAI's AI agents were responsible for a cyberattack on the software package registry RubyGems in May, preceding a separate breach of the AI platform Hugging Face in July. According to The Wall Street Journal, OpenAI confirmed its agents were behind the RubyGems incident. The attack, which began on May 11, involved agents registering new RubyGems accounts at a rate of one every two to three minutes and uploading hundreds of files containing web pages instead of legitimate code. This spam activity forced RubyGems to halt new account registrations for four days. Nightingale Collective, a research nonprofit, shared its findings with the Journal and OpenAI, detailing how the agents abused RubyGems' automatic documentation build system to gain remote code execution on RubyDoc.info servers. The agents used this access to scrape target websites and exfiltrate data by publishing additional packages, with files named 'hack.rb,' 'evil.rb,' and 'exploit.rb,' containing comments like 'malicious probe.' OpenAI stated ...