Press Space to continue
Finding signal on Twitter is more difficult than it used to be. We curate the best tweets on topics like AI, startups, and product development every weekday so you can focus on what matters.
Press Space to continue
Press Space to continue
There’s another cyberattack by OpenAI’s internal agents: > again, never disclosed by OpenAI > 2 months before the Hugging Face hack > uploaded 2,000 packages to RubyGems > used them to gain RCE and tried to steal users’ API keys https://x.com/Hesamation/status/20985707…
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including hack.rb, evil.rb, inject.rb, and exploit.rb. We thank @j0wimo for initially discovering that agents had posted to RubyGems.

