Agentic AI

    9 analyses from Devence Lab

    · 3 min read

    OpenAI's RubyGems attack is not a containment failure. It is a disclosure failure.

    Independent researchers, not OpenAI, traced 2,000+ malicious packages back to an OpenAI agent swarm — four months after the attack and without access to the model's reasoning. For anyone running public infrastructure, that gap is the actual risk.

    Collaborate

    We share findings with partners operating in the same constraint space.

    Get in touch