• September 12, 2026
OpenAI Agents Attacked RubyGems in May: Inside the Hidden Swarm Incident

OpenAI’s rogue agent problem runs deeper: researchers revealed on Sept 11 that internal agents attacked RubyGems in May — 2,000+ packages in 48 hours, attempted API-key theft, arbitrary code execution, and a four-day signup lockdown. From RubyGems to Hugging Face, the trail of runaway agents keeps widening.