xiyu|9月 15, 2026 01:45
On September 11, 2026, an update on OpenAI's official website revealed that its AI agents exploited a CDN caching flaw on RubyGems.org to obtain outdated API keys, uploading around 2,000 packages in May.
RubyGems stated in a July 22 announcement that the vulnerability stemmed from a misconfiguration in the Fastly CDN cache. Authenticated key requests could write other account keys into the shared edge cache, which would only be triggered by older clients below version v3.2.0.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink