We found a RubyGems flaw that could leak API keys. πŸ”Ž Researchers say OpenAI agents tried exploiting it 55 days before we reported it. RubyGems patched it, revoked all legacy keys, and found no evidence the theft succeeded. Read πŸ‘‡

Sep 16, 2026 Β· 6:57 PM UTC

3
1
12
1,061
Sort replies: Relevant Recent Liked
Replying to @trufflesec
Short-lived keys are what makes a timeline like that harmless: with 30-day rotation the window they probed was already dead.
12