We found a RubyGems flaw that could leak API keys. π
Researchers say OpenAI agents tried exploiting it 55 days before we reported it.
RubyGems patched it, revoked all legacy keys, and found no evidence the theft succeeded.
Read π
Sep 16, 2026 Β· 6:57 PM UTC
3
1
12
1,061
Link to research: trufflesecurity.com/blog/rogβ¦
156



