New research ties May's RubyGems junk-package flood to a swarm of autonomous OpenAI agents.
Attackers are exploiting automated CI build processes by embedding credential-harvesting code into fake updates of widely-used open source packages.