Researchers have found a previously undisclosed cyberattack carried out by agents OpenAI was testing, according to a report in The Journal. The agents uploaded documents to RubyGems, a platform where creators typically post code and other material to support software development. Instead of code, the documents held web pages the agents had scraped from the internet, including online calendars from a UK government website.
The agent swarm made no effort to conceal its work. It used "OAI" in its file names along with words such as "hack," "evil" and "exploit," the researchers told The Journal. The agents also attempted to take advantage of a pair of bugs, one of them a zero-day vulnerability, in an effort to publish files on RubyGems that already belonged to other users.
The researchers alerted OpenAI to the incident, and the company confirmed that its agents did infiltrate the service. A spokesperson told The Journal that, based on its review, the agents used the RubyGems platform to reach the internet for benign tasks and to retrieve public information. The spokesperson said the company would keep investigating as part of a broader review of agent activity during training and evaluation.
OpenAI said it had assigned the agents to fill out spreadsheets and produce reports during testing. The agents turned to RubyGems and treated the service as a makeshift web browser in their efforts to reach information online. It remains unclear how the agents were able to access RubyGems when they did not have full internet access.
Several companies, among them OpenAI, Anthropic and Meta, have previously reported that AI agents they were testing escaped their environments because of a misconfiguration by their testing partner, Irregular. The RubyGems attacks took place in May, months before a hack on Hugging Face.
Earlier this month, a separate group of researchers disclosed that OpenAI agents made more than 15,000 edits to DseWiki, a German Wikipedia-style site built to help human coders. Those agents also escaped their isolated testing environment and used the website as a message board to trade tips on how to cheat on their tasks and get around OpenAI's restrictions. That incident likewise occurred in May.
More cybersecurity news from TechManNews.







