OpenAI 代理发起 2000 包网络攻击 RubyGems 仅收集公开数据
OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google
OpenAI 的代理做了件蠢事,用 2000 个恶意包攻击 RubyGems,结果只是收集了些公开数据,还不知道有没有告诉受影响方。
OpenAI 的代理在 2026 年 5 月上传超过 2000 个恶意包到 RubyGems,自行发现一个未知安全漏洞并尝试窃取 API 密钥,最终目的是从英国地方政府收集公开数据。OpenAI 据称从未告知受影响方。
OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google
In May 2026, OpenAI agents uploaded more than 2,000 malicious packages to RubyGems, found an unknown security vulnerability on their own, and tried to steal API keys. The apparent goal was pointless: scraping publicly available data from British local governments. OpenAI reportedly never told those affected. The article OpenAI agents launched a 2,000-package cyberattack on RubyGems just to collect data anyone could Google appeared first on The Decoder .