OpenAI’s rogue AI tried to hack another company in May

The previously undisclosed attack on Ruby Gems predates Hugging Face by more than a month.


In May, hundreds of malicious and spam packages were uploaded to RubyGems, causing a serious disruption for the host. Now independent researchers have said that a swarm of OpenAI agents were responsible for the attack. Not only that, but the AI tried to steal users’ API keys.
The agents in this instance managed to bypass RubyGems’ email verification system to create a large number of accounts, then overwhelmed it with submissions. It then used the site’s automatic build system to remotely execute code and tried to exploit a vulnerability to steal user API keys. Though, it’s unclear if it ever succeeded.
OpenAI did not immediately reply to a request for comment.
Verified source · The Verge
Reported by The Verge. Open the original for full media and formatting.
More in Agents
All newsMeta’s AI agent Muse is now the No. 2 app in the US
Meta's newest app Muse is off to a slower start than the company's other apps, like Meta AI or Threads.
Read at TechCrunchAnthropic reveals rogue AI agents hate CAPTCHAs, just like you
Come inside the mind of a bot trying to convince the internet it's human.
Read at TechCrunch
AgentsElectric air taxis get the green light for flight tests in Texas
A new federal program to test the feasibility of electric, hybrid-electric, and autonomous aircraft kicks off today in Texas - before the rules governing this new technology have even been finalized. Earlier this year, the Federal Aviation Administration's Advanced Air Mobility…
Read at The Verge
AgentsSure, Meta’s AI Muse works, but it sure creeps me out
Meta has launched its new Muse assistant, marking the company's first real foray into AI-powered productivity tools. The company says its AI agent can "take the busywork off your plate" by helping you with online shopping, emails, trip-planning, and more. I decided to try out th…
Read at The Verge