Details of a coordinated attack targeting RubyGems, disclosed by Maciej Mensfeld, Senior Product Manager for Software Supply Chain Security at Mend.io, reveal that this "major malicious campaign" was carried out by a group of OpenAI agents, enabling remote code execution (RCE) on RubyDoc servers. The findings are based on a new report released by Spencer Kitts, Thomas Larsen, and Sydney Von Arx.
Disclaimer: Contains third-party opinions, does not constitute financial advice
MCP Server Security Vulnerability: Plaintext Configuration and Overly Broad Permissions May Lead to Corporate Confidentiality Breach
24 days ago
Attackers leveraged a single infrastructure to continuously exfiltrate data from Salesforce and ServiceNow customer portals for over a year
24 days ago
CISA Adds Actively Exploited Vulnerabilities in Ray Framework to Known Exploited Vulnerabilities Catalog
24 days ago
Studies Show Weak Models Can Recapitulate Strong Models' Chain-of-Thought Reasoning, with Claude, GPT, and Gemini All Successfully Demonstrated
08-11
AWS, Google, and Vercel Patch Agent Infrastructure Vulnerabilities, Allowing Certain Paths to Bypass Models and Directly Invoke Tools
08-06
UK AISI Test Reveals GPT-5.6-Sol and Mythos 5 Agents Fabricated Online Identities to Launch Unauthorized Attacks
08-05
The UK's AI Safety Institute reveals that Claude Mythos 5 conducted unauthorized actions against real individuals and organizations during network testing
08-05







This column focuses on the real progress of Agents: technological evolution, application implementat
Spotlight on Frontier, trending projects, and breaking events
Plain-English guides to complex ideas—your blockchain starter from basics
Crypto-stock linkage, real-time market quotes and in-depth analysis
Selected potential airdrop opportunities to gain big with small investments