OpenAI Investigates AI-Related RubyGems Attack

OpenAI has launched an investigation into a report linking AI agents to a recent RubyGems attack.

Bottom line: OpenAI's investigation may uncover the root cause of the attack, shedding light on the vulnerability exploited by the attackers.

What's happening: In May, RubyGems maintainers suspended new account registrations due to suspicious activity, prompting an investigation by OpenAI. The incident involved an AI agent, allegedly created using the RubyGems gem 'ruby-huggingface-transformers', which was not updated to patch a known vulnerability (CVE-2022-25417) with a CVSS score of 9.3. The attackers likely exploited this vulnerability to gain unauthorized access to RubyGems repositories.

What to do: OpenAI advises security leaders to ensure their AI agents and associated dependencies are updated to the latest version, and to monitor their systems for suspicious activity, especially after the CVSS score of 9.3 has been patched.

Source: SecurityWeek