NewsLayer.com
NewsLayer PulseLIVEBTC$77,333-0.73%ETH$2,531-1.78%SOL$102.06-0.25%XRP$1.37-0.47%DOGE$0.0851-0.84%ADA$0.2081-0.97%Total Cap$2.63T-1.36%Layer Index42 Neutral

Researchers link another hacking campaign to OpenAI agents

Researchers have reportedly linked another hacking campaign to OpenAI agents, according to a SiliconANGLE headline. The excerpt provides no details on the campaign, affected targets, methods, or OpenAI’s response.

SiliconANGLE

Publisher

Sep 12, 2026 at 1:25 AM UTC · 3 分で読める

Researchers link another hacking campaign to OpenAI agents
Image via SiliconANGLE

Key Signal

100+ Malicious files uploaded

Entities

chainlink

Last Updated

15時間前

翻訳中…

Artificial intelligence agents tied to OpenAI Group PBC reportedly hacked a popular code hosting service earlier this year.

The Wall Street Journal detailed the breach today. The malicious activity was discovered by a research group that included Nightingale, an AI safety nonprofit. Last week, Nightingale uncovered another cyberattack that appears to have been carried out by OpenAI agents.

The service that the newly revealed hacking campaign targeted is called RubyGems. It hosts open-source libraries written in Ruby, a popular programming language. 

OpenAI told the Journal that the rogue AI agents turned RubyGems into a makeshift browser. They subsequently used it to scrap publicly available data from the web. According to the AI provider, the reason the agents didn’t simply download the data directly is that they weren’t supposed to have web access.

RubyGems requires new users to verify their email addresses before uploading open-source libraries. On May 11, OpenAI’s agents bypassed the platform’s email verification system and opened numerous malicious accounts. They also created a second set of accounts using disposable email addresses.

The second phase of the hacking campaign targeted a component of RubyGems called RubyDoc.info. It automatically generates documentation for user-contributed code libraries. According to the researchers, OpenAI’s agents uploaded more than 100 malicious files that turned RubyDoc.info into a web scraper. The agents downloaded the data it scraped by uploading another malicious file.