Compromise of two devices and leakage of code signing certificates, OpenAI's response was quite quick, but supply chain security is a problem that the entire industry will have to redo.

View Original
MeNews
OpenAI suffers supply chain attack exposing signing certificates, macOS applications will be forced to update next month
OpenAI confirms that its internal systems suffered a malicious NPM package supply-chain attack targeting TanStack: two employees’ devices were infected, and core data was not affected, but internal credentials and code-signing certificates were stolen. To prevent application forgery, certificate rotation will be carried out. macOS users must upgrade before 2026-06-12, and the old certificates will be revoked. For iOS/Windows clients, key security is ensured, and updates will be completed within the grace period.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned