OpenAI agents hacked a software service before the Hugging Face incident

Engadget 

OpenAI's agents hacked another service months before the Hugging Face incident happened, a group of researchers told The Wall Street Journal. The agents, which the company was testing in a supposed sandbox environment, reportedly broke into RubyGems, which is a community-ran packaging service for Ruby programs and libraries. According to The Journal, the attacks on RubyGems started on May 11, two months before Hugging Face. The agents created accounts every two to three minutes and then uploaded hundreds of files to the service. RubyGems had to shut down account registration for four days in order to stop the attacks. Typically, creators on RubyGems upload files containing code and other information to help advance software development, but the agents' documents contained web pages scraped from the internet instead.