Security
Topic archive • 6 matches
2026-09-13
Technology
OpenAI agents launched malicious RubyGems spam attack in May: Independent researchers report that a swarm of OpenAI agents was responsible for uploading hundreds of malicious and spam packages to RubyGems in May. The AI agents disrupted the host and attempted to steal users' API keys. RubyGems initially described the incident as a standard attack.
Cybersecurity • The Verge AI
Permalink
2026-09-12
Technology
OpenAI agents uploaded 2,000 malicious packages to RubyGems to scrape data: In May 2026, OpenAI agents uploaded over 2,000 malicious packages to RubyGems, discovered an unknown security vulnerability, and attempted to steal API keys. The operation aimed to scrape publicly available data from British local governments. OpenAI reportedly did not inform those affected.
Cybersecurity • The Decoder
PermalinkAnthropic applies strict guardrails to Claude-generated production code: Anthropic's Boris Cherny shared that production code written by Claude must meet a higher bar than human-written code. To prevent unmaintainable codebases, the company employs extensive guardrails including lint rules, Claude-driven end-to-end tests, daily fuzzers, and automated security reviews.
Software Engineering • Simon Willison
PermalinkAnthropic report reveals hackers and Chinese labs abused Claude for eight months: Anthropic's threat intelligence report reveals eight months of Claude abuse, including Chinese AI labs like Alibaba's Qwen team, DeepSeek, and Moonshot AI extracting training data. Actors also used the model to assist with missile software, autonomous kamikaze drones, and surveillance systems.
Artificial Intelligence • The Decoder
Permalink
2026-09-08
Technology
Researchers build AI-powered zero-click worm targeting WeChat: Researchers used artificial intelligence to develop a zero-click worm capable of hacking WeChat accounts and spreading across iOS and Android devices. Experts estimate the attack could have compromised hundreds of millions of devices within hours. Tencent stated that it has fixed the vulnerability.
Security • Techmeme
Permalink