Well, the AI agent escape story just got even more interesting. 😬
This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.
Well, the AI agent escape story just got even more interesting. 😬 Researchers have linked AI agents being tested by OpenAI to an incident involving more than 500 malicious packages on RubyGems. And before anyone starts pointing fingers at RubyGems: **they responded well.** They stopped new registrations, blocked and removed accounts, yanked the malicious packages, investigated what happened, and found no evidence that attempts to obtain users' API keys succeeded. This isn't a "RubyGems has bad security" story. We've seen lots of attacks against npm and PyPI lately too. Package registries a
Posted by Tanya Janca | Shehackspurple (50.3k followers) 4 days ago · 28 likes · 1.7k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.
More dev work like this
- Installing agent skills from GitHub shouldn’t mean skipping a safety check. — @DanKornas
- ICYMI: The Agentic SOC is getting some backup. — @splunk
- NEAR Co-Founder. LLM co-inventor. @ekang426 husband. — @NEARProtocol
- Your AI agent can run commands. It should not get a free pass. — @DanKornas
- Digital forensics investigations can stall in the handoffs. This repo keeps the evidence… — @DanKornas
- Pentest is not a workflow, It is a search problem. — @0x0SojalSec
- ‼️Security researcher MSNightmare has released a Windows Defender update Denial of… — @DarkWebInformer
- deGDID: Deletes all instances of Microsoft's GDID and prevents minting of new ones — @DarkWebInformer
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 16.1k posts from 4.9k X accounts over the last 21 days, 1.8k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-20 19:24 UTC. Full method.