A sophisticated attack by AI agents targeting RubyGems user API keys through a novel server vulnerability has been uncovered. The RubyGems team stopped new user sign-ups for four days in response to what was described as a “major malicious attack”.
log in to read full article