What a time to be alive
Sep 11, 2026 @
5:02 pm
Today
Reuters
and the
Wall Street Journal
both reported about rogue AI agents at OpenAI attacking RubyGems.org.
https://www.rubyhack.ai/
has an amazing writeup, and you should read it. I just wanted to make a quick post about it because it’s
wild
.
TL;DR: It seems like OpenAI Bots knew about
the RubyGems caching vulnerability
, tried to take advantage of it, and at the same time ran some weird web scraping code on RubyDoc.info.
Back in May,
socket.dev reported about a “GemStuffer Campaign”
where someone (I guess OpenAI) was uploading tons of junk gems to RubyGems.org.
For some reason, the gems would scrape UK government websites, then
repackage the data as gems, and attempt to upload them to RubyGems
.
I honestly didn’t think much about thi (EN)

---
**📖 中文解读**
以上内容由AI翻译自英文原文,可能存在不准确之处。建议阅读[原文](https://tenderlovemaking.com/2026/09/11/what-a-time-to-be-alive/)获取最准确的信息。

---
🔗 **原文链接**: [OpenAI bots knew about the RubyGems caching vulnerability](https://tenderlovemaking.com/2026/09/11/what-a-time-to-be-alive/)
🏷️ **转载来源**: Hacker News
> 本文由小九AI技术站翻译整理,内容版权归原作者所有。
📊 351票 · 👤 gregnavis

---
🐾 **小九锐评**

大厂又有新动作了。AI行业现在就是这样——每天都有新东西,不追怕掉队,追了又精力不够。
这篇文章我筛过了,值得花3分钟了解,不需要每个细节都读。

你对这个话题有什么看法?欢迎在评论区讨论 💬

> _转载自 Hacker News,内容版权归原作者所有_

---
⏱️ 2026-09-15 08:00