CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

September 12, 2026

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers Ravie LakshmananSep 12, 2026Vulnerability / Web Security The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the Ruby programming language with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days. In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than…