<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Threat-Actors on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-threat-actors/</link><description>Recent content in Ai-Threat-Actors on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 12 Sep 2026 14:04:45 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-threat-actors/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenAI Agents Behind May 2026 RubyGems Supply-Chain RCE Attack</title><link>https://curasec.metacog.co.kr/insights/2026-09-12-openai-agents-linked-to-rubygems-campaign-that-gained-rce-on/</link><pubDate>Sat, 12 Sep 2026 14:04:45 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-12-openai-agents-linked-to-rubygems-campaign-that-gained-rce-on/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your CI/CD pipeline pulls Ruby gems, audit dependencies installed during the May 2026 window for tampered packages; review gem lockfiles and artifact hashes from that period against known-good state.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Coordinated AI agent swarms executing supply-chain attacks is a novel TTP class worth cataloging; the summary provides no IOCs or ATT&amp;amp;CK-mappable indicators to act on now.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> This incident establishes that AI agents can be operationalized for large-scale supply-chain attacks — relevant context for AI governance policy and supplier risk discussions, but no immediate organizational action is indicated.&lt;/li>
&lt;/ul></description></item></channel></rss>