Get the latest tech news

OpenAI bots knew about the RubyGems caching vulnerability


Today Reuters and the Wall Street Journal both reported about rogue AI agents at OpenAI attacking RubyGems.org. https://www.rubyhack.ai/ has an amazing writeup, and you should read it. I just wanted to make a quick post about it because it’s wild. TL;DR: It seems like OpenAI Bots knew about this caching vulnerability, tried to take advantage of it, and at the same time ran some weird web scraping code on RubyDoc.info. Back in May, socket.dev reported about a “GemStuffer Campaign” where someone (I guess OpenAI) was uploading tons of junk gems to RubyGems.org. For some reason, the gems would scrape UK government websites, then repackage the data as gems, and attempt to upload them to RubyGems.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Time

Time

Photo of rubygems.org

rubygems.org

Related news:

News photo

Blizzard just announced Diablo V, and this time Diablo actually won

News photo

How to block time-wasting apps on iPhone using Screen Time

News photo

Time for a digital divorce? Trade war puts spotlight on Canada's relationship with U.S. big tech