RubyGems Open Source Supply Chain Security and OpenAI
rietta
45 points
6 comments
September 14, 2026
Related Discussions
Found 5 related stories in 74.4ms across 6,607 title embeddings via pgvector HNSW
- OpenAI agents carried out an undisclosed attack on RubyGems chao- · 551 pts · September 11, 2026 · 66% similar
- OpenAI bots knew about the RubyGems caching vulnerability gregnavis · 421 pts · September 14, 2026 · 66% similar
- Disrupting supply chain attacks on NPM and GitHub Actions nyku · 87 pts · July 29, 2026 · 57% similar
- Rails Is Built for AI cdnsteve · 16 pts · August 13, 2026 · 55% similar
- Ruby 4.0 Universal RCE Deserialization Gadget Chain pentestercrab · 74 pts · August 14, 2026 · 52% similar
Discussion Highlights (4 comments)
thomascountz
Related: What a time to be alive – rouge AI agents attack RubyGems.org (tenderlovemaking.com) - https://news.ycombinator.com/item?id=49695876 - Sept 2026 (123 comments)
rietta
Unrelated to the content of this post, I fixed the website header to be much smaller and unobtrusive while reading. Tested on my iPhone and in the Firefox responsive simulator as promised in the comments there.
devy
Two chilling effects Mr. Rietta brought up that are legit and happening right now: 1. "When a critical CVE is published impacting a publicly accessible system, think again. You have hours at most. All organizations have to process changes to match this reality on the ground." 2. “AIs are also good at reverse-engineering exploits from patches, which means that these vulnerabilities will be weaponized as soon as the update is published.” Yes, it helps defenders long term but in the short term it is a weapon most are not ready for.
lrvick
Neat. Do Homebrew, Alpine, and NixPkgs next! Yolo projects like those are never going to learn until the supply chain attacks actually happen, and I long ago gave up trying to convince them. From a safe distance, I am finding myself rooting for AI agents to speedrun the attacks because no one listens. Maybe on the other side we can finally normalize sane software distribution practices.