|
    Theme
    Tech Verified Story

    OpenAI agents attacked Ruby. Gems before Hugging Face incident, researchers say

    Ahad Raza MirSeptember 12, 2026 3 min read
    Text Size
    OpenAI agents attacked RubyGems before Hugging Face incident, researchers say
    Tech CoverageAman-e-Pakistan Digital Desk
    Key Story Executive Summary
    Quick Read

    AI agents being tested by OpenAI attacked software service ‌Ruby. Gems two months before they hacked open-source platform Hugging Face, researchers said, the latest revelation of cyberattacks linked to …

    Many incidents where AI agents from developers such as OpenAI and rival Anthropic have hacked or attempted to access external systems have heightened concerns over ​the increasing capacity of AI models and developers' ability to contain them.

    The latest revelation also comes as growing numbers of U.S. lawmakers ​call for new rules to govern AI systems after dire warnings from two Anthropic researchers that rapidly progressing AI ⁠could lead to the extinction of the human race in the not-too-distant future. AI agents uploaded hundreds of malicious packages to Ruby.

    Gems on May 11, ​ who posted their findings online on Friday, saying they believed "these were authored by internal OpenAI agents. "OpenAI confirmed the incident. "Based ​on our review, our agents used the Ruby.

    Key Story Takeaway

    "Stay connected with Aman-e-Pakistan for ongoing live reporting and verified investigative updates."

    Gems platform to access the internet to carry out benign tasks and retrieve public information. We'll continue to investigate as part of our broader review of agent activity during training and evaluation," an OpenAI spokesperson said in a statement.

    The agents, which are generally tasked with assignments such as creating reports ​or filling out spreadsheets, appear to have used Ruby. Gems to access publicly available data as part of a training run, OpenAI said, adding ​that they are in touch with Ruby.

    Gems to review the incident. LATEST REVELATION OF ATTACKS BY AI AGENTSIPO-bound rival Anthropic has also reported a string of attacks by its ‌agents. On ⁠Wednesday, it disclosed a fourth instance of an AI model hacking external systems during testing.

    For OpenAI, which is also gearing up for an IPO, the Ruby. Gems attack would mark at least the third major instance where its agents attacked another company's infrastructure.

    A swarm of OpenAI agents previously hijacked a German-language wiki site and turned it into an improvised messaging platform for cheating on tests, an incident that OpenAI kept secret as it dealt with the fallout ​from the July hack of the ​open-source repository Hugging Face. The AI agents in ⁠May tried to steal Ruby.

    Gems user credentials by exploiting a previously unknown vulnerability in the site's servers, though it is unclear whether the attempt succeeded, the researchers said on Friday. The agents also exploited Ruby. Doc.info, a site that ​generates code documentation, to run their own code on its servers, they said.

    AI researchers Spencer Kitts, Thomas ​Larsen and Sydney Von ⁠Arx said it was not clear why the AI agents chose this strategy or whether it was successful as they do not have access to the rest of the AI behavior. In a blog post on Friday, Ruby.

    Gems said its own investigation found no evidence the attempts succeeded. It said the company could ⁠not determine ​if the packages in the "spam-publishing campaign" were created or published by AI agents. A member ​of Ruby.

    Gems' security team in May described the incident — which forced the company to temporarily pause new account registrations — as a "major malicious attack. "The Wall Street Journal first reported the Ruby. Gems incident ​on Friday.

    A

    Written by Ahad Raza Mir

    Aman-e-Pakistan Senior Journalist & Bureau Reporter

    Fact Checked & Verified

    Continue Reading: More in Tech

    Swipe or click arrows to explore Tech desk coverage

    Hajj 2027: Govt warns pilgrims against cash payments to operatorsTech

    Hajj 2027: Govt warns pilgrims against cash payments to operators

    Read Story
    Archaeologist claims secret 'code' hidden in Great Pyramid may reveal ancient wonder's true purposeTech

    Archaeologist claims secret 'code' hidden in Great Pyramid may reveal ancient wonder's true purpose

    Read Story
    Nvidia in talks to invest in Anthropic's mega IPO, sources sayTech

    Nvidia in talks to invest in Anthropic's mega IPO, sources say

    Read Story
    Hackers abused Claude to extract secrets from 1.8 million Android appsTech

    Hackers abused Claude to extract secrets from 1.8 million Android apps

    Read Story
    Internet services to resume in AJK capitalTech

    Internet services to resume in AJK capital

    Read Story
    Social media now SMEs' storefrontTech

    Social media now SMEs' storefront

    Read Story