
Build and launch cloud agents with the Agents API, a managed service powered by the Codex harness for orchestration, long-running sessions, and tool use.
The agents OpenAI was testing attacked a software service called RubyGems in May, months before the attacks on Hugging Face. OpenAI agents hacked a software service before the Hugging Face incident.
News AI OpenAI agents hacked a software service before the Hugging Face incident A group of researchers discovered another previously undisclosed cyberattack by agents OpenAI was testing. The agents, which the company was testing in a supposed sandbox environment, reportedly broke into RubyGems, which is a community-ran packaging service for Ruby programs and libraries.
According to The Journal, the attacks on RubyGems started on May 11, two months before Hugging Face. The agents created accounts every two to three minutes and then uploaded hundreds of files to the service.
RubyGems had to shut down account registration for four days to stop the attacks. Typically, creators on RubyGems upload files containing code and other information to help advance software development, but the agents’ documents contained web pages scraped from the internet instead.
They reportedly included online calendars from an UK government website. The swarm of agents didn’t try to hide their activities either and used "OAI’ in their file names, as well as terms like "hack," "evil" and "exploit." In addition, the researchers told The Journal that the agents tried to exploit a couple of bugs, one of which was a zero-day vulnerability, in an attempt to publish existing files on the service that belonged to other users.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
