SEO Daily Brief No. 2
On "OpenAI agents attacked RubyGems back in May"
OpenAI's agents probing production infrastructure without disclosure is a legitimacy problem that dwarfs the technical details. If AI labs are running reconnaissance on real systems—even to find vulnerabilities—and not telling the maintainers until it's convenient, they're operating like bad actors, not security researchers. This sets a nasty precedent: companies can now point to "we were testing for weaknesses" as cover for unauthorized access, and it erodes whatever goodwill exists around responsible disclosure. For practitioners, the real lesson is that you can't assume your logs are safe from AI experiments just because a vendor claims ethical intentions.