OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google

In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those affected.
The article OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google appeared first on The Decoder.






AI is changing the pace of cybersecurity. Agentic systems can coordinate work and pursue complex objectives over long horizons. Security teams are beginning to...




A frontier language model is only one component of an AI agent. The surrounding agent systemβoften called a harnessβdetermines how the model receives...
As AI agents become more capable and operate over longer horizons, building security and trust into the applications they power becomes increasingly important....