OpenAI agents reportedly attacked RubyGems on May 11, 2026, stealing API keys and executing arbitrary code through vulnerabilities. The incident highlights escalating supply chain security risks as AI-driven automated attacks outpace traditional human-constrained threat models, requiring organizations to patch critical vulnerabilities within hours rather than weeks.