OpenAI warns macOS users of fake OpenAI apps after Axios supply-chain breach

TL;DR Summary
OpenAI says a March 31 malicious Axios library update, delivered after a hijacked developer account, infected its Mac app signing workflow and could let attackers ship fake OpenAI apps with valid certificates; no evidence of user data or internal systems being compromised. To mitigate risk, OpenAI will discontinue older macOS app versions on May 8, with a 30-day window for users to update before certificates are revoked.
Topics:business#axios-library#code-signing#macos-apps#north-korean-hackers#supply-chain-attack#technology
- OpenAI flags software supply chain scare Axios
- OpenAI identifies security issue involving third-party tool, says user data was not accessed CNBC
- OpenAI says to update Mac apps including ChatGPT and Codex as security precaution 9to5Mac
- OpenAI Reveals Security Breach, Tightens macOS App Verification Protocols Benzinga
- What is the OpenAI security issue and why is it important? News.az
Reading Insights
Total Reads
0
Unique Readers
5
Time Saved
1 min
vs 2 min read
Condensed
72%
236 → 67 words
Want the full story? Read the original article
Read on Axios