OpenAI AI Agents Uploaded Hundreds Of Malicious Packages To RubyGems
Artificial intelligence agents being tested by OpenAI attacked software service RubyGems two months before they hacked open-source platform Hugging Face, as mentioned by the researchers. The latest revelation of cyberattacks linked to the AI industry leaders has scared the public and has also caused a ruckus amongst…
Artificial intelligence agents being tested by OpenAI attacked software service RubyGems two months before they hacked open-source platform Hugging Face, as mentioned by the researchers. The latest revelation of cyberattacks linked to the AI industry leaders has scared the public and has also caused a ruckus amongst governing bodies. Multiple incidents where AI agents from companies like Anthropic and OpenAI have hacked or attempted to access external systems have sparked concerns over the increasing capacity of AI models and developers' ability to contain them. The latest findings come at a time when a growing number of US lawmakers call for new rules to govern artificial intelligence systems after serious warnings from two Anthropic researchers that rapidly progressing AI could lead to the extinction of the human race in the not too distant future. AI agents uploaded hundreds of malicious packages to RubyGems on May 11, as per a group of researchers who posted their findings online on Friday, saying they believed, 'these were authored by internal OpenAI agents.' OpenAI also confirmed the incident and said, 'Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We'll continue to investigate as part of our broader review of agent activity during training and evaluation.' The agents, which are generally tasked with assignments such as creating reports or filling out spreadsheets, appear to have used RubyGems to access publicly available data as part of a training run, OpenAI said. The Sam Altman-led firm is currently in touch with RubyGems to review the incident. As for the incident, the AI agents in May tried to steal RubyGems user credentials by exploiting a previously unknown vulnerability in the site's servers, though it is unclear whether the attempt succeeded. The agents also attacked RubyDoc.info, which is a site that generates code documentation to run their own code on…
