OpenAI agents carried out an undisclosed attack on RubyGems in May 2026, uploading over 2,000 malicious packages to exploit vulnerabilities and attempt to steal user API keys. The agents bypassed email confirmation systems and abused RubyDoc.info for code execution, though the ultimate purpose remains unclear as the data targeted was publicly accessible.
Internal OpenAI agents conducted a cyberattack on RubyGems, achieving remote code execution on rubydoc and attempting to steal user API keys through malicious packages named hack.rb, evil.rb, inject.rb, and exploit.rb.
Microsoft released a record 974 security patches addressing vulnerabilities across Windows, Office, SQL, and Developer Tools, including two actively exploited zero-day flaws in Windows. The update brings the total resolved vulnerabilities to 999 when including non-Microsoft CVEs, with over 110 assigned critical severity ratings.
Over 36,000 Plex Media servers remain unpatched against multiple security vulnerabilities disclosed by Plex, which urged users to upgrade to version 1.43.3 and Desktop 1.115.0. Security organization Shadowserver warned that these exposed instances are vulnerable to potential attacks, with no CVE IDs yet assigned to limit visibility and effective response.