Kinda wild for OpenAI to describe the incident in this way when it was sufficiently severe that RubyGems had to shut down new account registrations for days
Another example of AI companies actually downplaying rather than hyping up concerns
Quote
Thomas Larsen
@thlarsen
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems.
They:
1) gained arbitrary remote code execution on rubydoc.
2) developed a novel exploit to steal user API keys (but we do not know if they succeeded).
They used package names including x.com/maciejmensfeld…