RubyGems Open Source Supply Chain Security and OpenAI

(rietta.com)

40 points | by rietta 2 hours ago ago

5 comments

  • devy 7 minutes ago

    Two chilling effects Mr. Rietta brought up that are legit and happening right now:

    1. "When a critical CVE is published impacting a publicly accessible system, think again. You have hours at most. All organizations have to process changes to match this reality on the ground."

    2. “AIs are also good at reverse-engineering exploits from patches, which means that these vulnerabilities will be weaponized as soon as the update is published.” Yes, it helps defenders long term but in the short term it is a weapon most are not ready for.

  • thomascountz an hour ago

    Related:

    What a time to be alive – rouge AI agents attack RubyGems.org (tenderlovemaking.com) - https://news.ycombinator.com/item?id=49695876 - Sept 2026 (123 comments)

  • rietta an hour ago

    Unrelated to the content of this post, I fixed the website header to be much smaller and unobtrusive while reading. Tested on my iPhone and in the Firefox responsive simulator as promised in the comments there.