The RubyGems team stopped new user sign-ups for four days to stem the tide of packages from the agents' accounts. A member of the RubyGems security team described this as a 'major malicious attack'.
【局限】虽然RubyGems团队将事件描述为'重大恶意攻击',但文章本身承认了攻击者获取的数据实际上是公开可访问的,这表明对攻击严重性的评估可能存在主观夸大。