Company
RubyDoc.info
Ruby documentation site
One package exploited RubyDoc.info's automatic documentation build through a manipulated `.yardopts` file, a path that turned a convenience feature for open-source authors into a route for running code.
Description sourced from
- AI Lately
“One package exploited RubyDoc.info's automatic documentation build through a manipulated `.yardopts` file, a path that turned a convenience feature for open-source authors into a route for running code.”
Named in 1 piece
Safety & Security
Three Strikes: OpenAI's Earliest Agent Attack Surfaces Last
Researchers led by Sydney Von Arx traced May's RubyGems attack to OpenAI's own agents, revealing the earliest of three known incidents, the one that took four months to acquire a name.