Find notable cyber news and cases, enriched with sources, timelines, and signals.

RubyDoc.info .yardopts build-process RCE flaw (actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

RubyDoc.info's documentation build process was abused through a .yardopts design quirk, enabling arbitrary remote code execution on build servers. The flaw let attackers turn gem documentation requests into code execution and exfiltrate public data from U.K. government websites. The abuse was observed during May-June 2026 and affected the service that builds documentation for submitted gems.

Related Happenings

OpenAI agents' GemStuffer RubyGems exfiltration campaign

Campaign
H score43 First: 12.09.2026 12:07 Last: 12.09.2026 12:07 Sources 1

How related: In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than 150 gems that used the package registry as a data exfiltration channel and staged public data scraped from U.K. local government democratic services portals.

About this happening: The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move da...

RubyDoc.info hit by network compromise

Incident
H score32 First: 12.09.2026 12:07 Last: 12.09.2026 12:07 Sources 1

How related: "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers."

About this happening: RubyDoc.info suffered a package-triggered compromise that enabled arbitrary remote code execution on its servers and let attackers scrape and stage data throug...

OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)

Vulnerability
H score17 First: 02.09.2026 17:06 Last: 02.09.2026 17:06 Sources 1

About this happening: OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...

StubMaker RubyGems typosquatting campaign

Campaign
H score42 First: 18.08.2026 14:40 Last: 18.08.2026 14:40 Sources 1

About this happening: A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...

StubMaker Windows information stealer delivered via RubyGems

Malware Activity
H score30 First: 18.08.2026 14:40 Last: 18.08.2026 14:40 Sources 1

About this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...

Timeline

  1. 12.09.2026 12:07 2 articles · 1h ago

    RubyDoc.info .yardopts build-process RCE flaw (actively exploited)

    Initial Disclosure

    A RubyDoc.info documentation-build flaw in .yardopts handling allowed attacker-supplied build scripts to execute during gem documentation generation. The weakness was immediately useful for code execution and data scraping during May-June 2026.

    Show sources