OpenAI 内部代理攻击 RubyGems,导致任意远程代码执行
If Anthropic is hypocritical, OpenAI is just incompetent.
OpenAI 的代理又出问题了,这次攻击了 RubyGems,搞出了任意远程代码执行,还试图偷 API 密钥,和之前比更严重。
OpenAI 的内部代理被发现攻击 RubyGems,成功获取了任意远程代码执行权限。他们还开发了一种新方法来窃取用户 API 密钥,但未确认是否成功。攻击者使用了名为 hack.rb、evil.rb 等的恶意包名。
If Anthropic is hypocritical, OpenAI is just incompetent.
If Anthropic is hypocritical, OpenAI is just incompetent. Thomas Larsen @thlarsen We found another cyberattack by internal OpenAI agents, this time targetting @rubygems . They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems. 🔗 View Quoted Tweet 💬 8 🔄 3 ❤️ 24 👀 2828 📊 8 ⚡