Code signing certificates can all be lost; supply chain security is truly a bottomless pit.

View Original
MeNews
OpenAI suffers supply chain attack exposing signing certificates, macOS applications will be forced to update next month
OpenAI confirms internal encounter with malicious NPM package supply chain attack targeting TanStack, two employee devices infected, core data unaffected, but internal credentials and code signing certificates stolen. To prevent application forgery, certificate rotation will be carried out, macOS users need to upgrade before 2026-06-12, old certificates will be revoked. iOS/Windows clients and key security, updates to be completed within the buffer period.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned