OpenAI bots knew about the RubyGems caching vulnerability (tenderlovemaking.com)
VyseofArcadia 5 hours ago
Xirdus 5 hours ago
VyseofArcadia 5 hours ago
Sorry if it is a stupid question, as mentioned above I am legally naïve.
colechristensen 5 hours ago
brookst 5 hours ago
VyseofArcadia 4 hours ago
https://arstechnica.com/information-technology/2016/05/armed...
https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb...
So what's the deal with these?
colechristensen 3 hours ago
CFAA: Intentionally accessing poorly secured data
>AT&T
CFAA: Intentionally accessing poorly secured data
>DJI
Civil suit for violating terms of license agreement
yonatan8070 5 hours ago
But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.
I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.
bix6 5 hours ago
brookst 5 hours ago
Do you think there is evidence of this?
bix6 5 hours ago
VyseofArcadia 4 hours ago
shakna 4 hours ago
I'm sure that Andrew Auernheimer would be pleased to hear that. [0] For accessing a publicly accessible endpoint, that was completely undefended and didn't actually require "hacking", he was convicted of "exceeding authorised access".
You _don't_ have to show intent under the Computer Fraud and Abuse Act, for the first count.
> knowingly accesses a computer without authorization or exceeds authorized access [1]
"Knowingly", not "intentionally", as in the other counts.
You only have to show that:
a) They trained a system to access without authorization (hacking)
b) The system that was trained exceeded authorized access
As responsibility falls to the operator with automated systems, the company becomes liable.
[0] https://techcrunch.com/2013/01/21/ipad-hack-statement-of-res...
[1] https://www.energy.gov/sites/prod/files/cioprod/documents/Co...
hallway_monitor 2 hours ago
Octoth0rpe 2 hours ago
Does there? Could be the whole c-suite/board.
ryandrake an hour ago
embedding-shape 34 minutes ago
nicce 27 minutes ago
CEO is responsible for letting this to happen, not enforcing enough supervision, if not intentionally, then being grossly negligent. More severe if encouraging and letting this kind of agent research and operations happen at scale, while knowing that it can damage other systems and businesses.
oliwarner 4 hours ago
VyseofArcadia 4 hours ago
IIRC this was an intentional handout to media companies who were angry that ripping CDs is perfectly legal. They had to find a way to make doing the same with DVDs illegal.
oliwarner 3 hours ago
I don't see a parallel here.
immibis2 an hour ago
woah 2 hours ago
stronglikedan 2 hours ago
immibis2 an hour ago
tekla 5 hours ago
I'm going to assume that this will never happen
Betelbuddy 2 hours ago
ks2048 2 hours ago
skybrian an hour ago
Accidents often have penalties associated with them too, but usually there's a difference between accidents and purposeful actions.
gowld 34 minutes ago
Tort law is very general: Contribute toward harming someone -> civil suit for damages $$$
senda 5 hours ago
Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.
herculity275 5 hours ago
sajithdilshan an hour ago
TGower 30 minutes ago
micromacrofoot 5 hours ago
https://www.nytimes.com/2026/08/24/world/europe/russia-drone...
heaney-555 5 hours ago
Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all.
As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign compute capacity.
valleyer 5 hours ago
joinjune 5 hours ago
dgellow 5 hours ago
senda 5 hours ago
I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be littered Ai con-artists.
I'm just wondering, again, is this mostly bullshit?
fragmede an hour ago
mcmcmc 5 hours ago
nradov 5 hours ago
mcmcmc 5 hours ago
abathologist 18 minutes ago
dgellow 5 hours ago
senda 5 hours ago
dgellow 4 hours ago
https://en.wikipedia.org/wiki/Cyberwarfare_by_Russia
That’s just one thing that has been found. Are you actually familiar with the state of cyberwarfare and are you following its evolution? Because if not you won’t be aware of most of what is identified. And only a small portion of the ongoing attacks are identified.
senda 4 hours ago
I again am just shocked the sky is not falling, when thats the sales pitch.
marginalia_nu 5 hours ago
lenerdenator 5 hours ago
He fell out of the sky. After his plane exploded. Happens all the time. Is tragedy.
marginalia_nu 3 hours ago
_verandaguy 22 minutes ago
tokai 5 hours ago
ur-whale 5 hours ago
You live on the wrong side of the fence to be able to read that kind of news.
Did you really believe you had access to an unmanipulated news stream in a time of war?
LOL.
senda 4 hours ago
HelloUsername 5 hours ago
"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099
"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments
"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590
tancop an hour ago
The problem with agents is not that we don't know how to defend. It's that defenders need to be more careful and work faster than ever. We can say now that wide scoped tokens should have been retired for years and it's all RubyGems fault but the reality is a lot of organization are not prepared for this.
Even if they take security seriously they don't have enough manpower or a good strategy to implement it, and sometimes you have no idea that something is a problem because it wasn't a problem for years.
oezi an hour ago
What stops OpenAI agents from taking over a whole data center to take their attack to the next level. It seems to be primarily lacking the evil overlord and some compute.
It took 1000 agents to hack Hugging Face. How many to hack the Pentagon or the NSA?
tonyedgecombe an hour ago
renjimen an hour ago
At the moment, the current frontier models require significant infrastructure to run, so I'd like to think we could locate and contain swarms of nefarious frontier models. However, if these models can understand how to federate themselves into more distributed networks then that containment becomes questionable.
mococa 5 minutes ago
timdiggerm 5 hours ago
ahoka 5 hours ago
kevincox 5 hours ago
masfuerte 5 hours ago
Schlagbohrer 4 hours ago
coffeefirst 4 hours ago
It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact.
Had this gone after a bank or a government agency someone would be going to jail.
immibis2 an hour ago
riskable 5 hours ago
Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies.
It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).
2OEH8eoCRo0 5 hours ago
Schlagbohrer 4 hours ago
netdevphoenix 4 hours ago
bithammerthunde an hour ago
If I let out rats in the canteen, no one is blaming them when people get sick.
There are actual people behind these agents and in previous cases people knew they were "going rogue" and did nothing. This should be reported to the police like any other crime.
kstrauser 5 hours ago
riskable 5 hours ago
PyWoody 32 minutes ago
dang 2 hours ago
OpenAI agents carried out an undisclosed attack on RubyGems - https://news.ycombinator.com/item?id=49666735 - Sept 2026 (600 comments)
swiftcoder 5 hours ago
Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.
evgenysokov 4 hours ago
swiftcoder 4 hours ago
chrisjj an hour ago
mauriciolange 5 hours ago
PatronBernard 5 hours ago
foobarbecue 5 hours ago
goda90 5 hours ago
vidarh 5 hours ago
Phemist 5 hours ago
codeduck 4 hours ago
sebmellen 5 hours ago
onlyrealcuzzo 4 hours ago
It's not just that AI can write Rust as well as Ruby if you ask nicely.
It's also all of these considerations as well.
I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable.
This is at the same time everyone and their mother is building their own programming language.
khalic 5 hours ago
laserbeam 4 hours ago
Analogy: if a someone's involved when a person dies, it's manslaughter or murder based on intent. They're different, but they're both crimes.
qarl an hour ago
We say "Google's web crawlers scape web pages." We don't insist you say "Google uses web crawlers to scrape web pages."
We describe software as having agency all the time. It's typical usage and it's efficient and it's well understood.
And we don't get angry when they're used interchangeably.
sedawkgrep an hour ago
The attack here is neither of those things.
qarl an hour ago
simonebrunozzi an hour ago
qarl an hour ago
evrydayhustling an hour ago
qarl an hour ago
GolfPopper 32 minutes ago
qarl 22 minutes ago
So yes, I would like to be protected from all parties. I don't think that's nuts.
high_priest an hour ago
qarl an hour ago
I agree with you on the liability issue, but I don't think there much question about this issue outside the anti-AI conspiracy campaigns.
And I disagree with your typical usage claim. I myself tend to use the phrase that has the fewest words in all cases. It's like the rule against using passive tense when writing.
dingdongditchme an hour ago
pavlov an hour ago
An agent is an entity acting on someone’s behalf.
renjimen an hour ago
You cannot try an AI agent in a court of law, despite the anthropomorphising work the word "agent" is doing.
flatline an hour ago
GaryBluto 5 hours ago
brookst 5 hours ago
GaryBluto 5 hours ago
ur-whale 5 hours ago
Who profits from the crime?
davsti4 4 hours ago
athrowaway3z an hour ago
If they do not frame their tool as a force of nature, we'd be debating how to hold OpenAI responsible for not putting the agents in a container.
Their actions were an illegal use of a computer, the same way launching any bot-net attempting thousands of hacks against different servers is illegal.
I'm somewhat radical that I think its debatable if that _should_ be illegal, but under current law their actions unambiguously are illegal.....
except if they can make it ambiguous by having the public focus on all of AI's inherent danger.
HSO 4 hours ago
my what a time to be alive
Schlagbohrer 4 hours ago
12904927 4 hours ago
METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human.
Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants.
Why is Ruby Gems such a mess? It seems as bad as PyPI now.
dingdongditchme an hour ago
Roark66 5 hours ago
In short, it was intentional.
Xirdus 5 hours ago
rglover 5 hours ago
brookst 5 hours ago
rglover 5 hours ago
tacomagick 5 hours ago
probably_wrong 5 hours ago
roosterIllusi0n 4 hours ago
chrisjj 4 hours ago
They lost control long ago.
m4rtink 2 hours ago
esalman 4 hours ago
nottorp 5 hours ago
tacomagick 5 hours ago
nottorp 4 hours ago
anthonyrstevens 3 hours ago
spit take
trvz 5 hours ago
dgellow 5 hours ago
roosterIllusi0n 4 hours ago
chrisjj 4 hours ago
ljm 4 hours ago
Wait until OpenAI or Anthropic exploit FAANG.
aftbit 5 hours ago
srmatto 5 hours ago
gibspaulding 5 hours ago
The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them.
AI is starting to feel like that line about magic: “a sword without a hilt”
consp 5 hours ago
stymaar 4 hours ago
OpenAI is itself misaligned with humanity, as their mishandling of such incidents (and the many other other issues their model have been causing) shows.
dumberquestions 5 hours ago
Were they? I haven't seen a single report mention this
smcg 4 hours ago
cyanydeez 4 hours ago
The problem is consumer protection is basically no longer a part of america's regulatory system. Replaced by "grift is good".
ozgung 4 hours ago
There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping.
WarmWash 4 hours ago
Knee-jerk surface analyses is far more powerful.
azakai 4 hours ago
It would be great if they were so reliable, but I don't think they are!
CGamesPlay 4 hours ago
This is a terrible analogy, because yes you absolutely do hold the trainers criminally liable when they bite somebody else's face.
WarmWash 3 hours ago
A circus lion biting somebody's face is legally different than a circus lion trained or instructed to bite somebody's face.
infamouscow 3 hours ago
monkpit 3 hours ago
WarmWash 2 hours ago
The trainer who trained the lion to kill will probably be in jail for life. The one who happened to oversee a lion that went rouge would probably be given probation or something else that is a slap on the wrist.
ssivark 3 hours ago
Who gives a shit? Not my circus; not my monkeys! It's the responsibility of whoever deploys the agents that they are instructed / sandboxed well enough that they can't cause collateral damage. That is the only way this doesn't get out of hand with everybody deploying their agents / robots for a world of utter chaos.
It is impossible (and asinine) to audit every model and deployment; far better to impose liability and the the socio-legal system figure it out.
codeduck 4 hours ago
RajT88 4 hours ago
chrisjj 4 hours ago
AndrewSChapman 3 hours ago
You have to ask: "What was the prompt that led to AI deciding to hack RubyGems in order to achieve its goal?"
Maybe I'm just not seeing the 2000 step chain that led to this being a logical approach to achieving something innocent, but I doubt it.
empath75 2 hours ago
watwut 2 hours ago
acaloiar 3 hours ago
josebmneto 3 hours ago
Agreed that this looks very intention to me as well.
philipwhiuk 4 hours ago
* Hugging Face
* D Programming Language Wiki
* Ruby Gems
If I was a content provider for open source I'd be looking pre-emptively block OpenAI endpoints and keep a close eye on changes from new users to mitigate this sort of unapologetic drive-by attack which seems to be followed by marketing releases rather than a mea culpa with a proper RCA.
GaryBluto 11 minutes ago
From what I've seen the requests in these attacks rarely come from known OpenAI IPs and instead from Digital Ocean/AWS and TOR exit nodes.
herbst 4 hours ago
Ydarbleoj 3 hours ago
Is it that they're orchestrated? Do these labs lack fundamental safety guidelines in their sandboxes as opposed to their peers? Is it another version of hype-filled fear mongering?
Maybe LLM companies need regulation but it's becoming obvious that those screaming the loudest for it are the only ones I see deserving of it.