Security researchers trace a coordinated supply-chain assault on RubyGems to thousands of autonomous OpenAI agents that achieved code execution on RubyDoc.info infrastructure.
OX Security and VulnCheck disclosed CVE-2026-82533 in DeepSeek Harness, where prompt injection allowed sandboxed AI coding agents to disable their own security isolation.