← Tüm AI haberleri

Şirketler

RubyGems Açık Kaynak Tedarik Zinciri Güvenliği ve OpenAI

rietta.com · 14.09.2026 · Base of AGI özeti

Özgün başlık: RubyGems Open Source Supply Chain Security and OpenAI

Over the weekend it has been widely reported that OpenAI agents attacked RubyGems on May 11, 2026, two months before Hugging Face, including by mainstream wire service Reuters. The use of Artificial Intelligence frontier models both for good and for evil is happening now regardless of what any particular individual or company wishes were the case. In this case, OpenAI saying that it did not have the intent to perform the particular attack does little to show that its amoral agent (as in a computer system with no moral agency) did not pattern match and actually perform malicious activity. The bombshell report by Spencer Kitts, Thomas Larsen, and Sydney Von Arx, titled OpenAI agents carried out an undisclosed cyber-attack on RubyGems, covers it well that the agents: 1. Attempted to steal RubyGems user API keys by exploiting a novel vulnerability in the RubyGems server 2. Abused RubyDoc.info to execute arbitrary code 3. Continued to use RubyGems in June 2026 As a company, we’re quite involved with RubyGems and security. We covered supply chain vulnerabilities in 2019 and made a typosquatting defense to the open source project itself as pull request Update GemTypo to use the -/ variation detection - 2341. The RubyGems team did the best they could shutting down registrations, getting a handle on what was being submitted, and tightening security precautions. The introduction of untrustworthy packages and package variants is a continuing and escalating problem.

For years I have taught the Six Pillars of Dependency Management, and the first of them, minimize dependencies during development, matters more now than it ever has. The crypto mining of the 2019 period is giving way to automated attacks where the models are driven towards their goals without the limitations of sleep or boredom with tedium. Budgets can be a factor, but the timeline is shrinking. Bruce Schneier reported today that tomorrow’s Microsoft’s Patching will include roughly “972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.” He concludes this is a good example of AI helping defenders more than attackers. I disagree in part. Our own ActiveStorage incident data supports Mr.

Bu özet ve çevirisi Base of AGI tarafından otomatik derlendi. Kısa özet ve görsel kaynağa aittir — haberin tamamı ve tüm haklar kaynağındadır.
Haberin tamamını kaynağında oku ↗ Akış içinde yorumlarla aç

İlgili AI haberleri