OpenAI’s Mac apps need updates thanks to the Axios hack
ID: 29580550-1c8d-5ed9-a254-344abf0c72d4
STIX ID: report--29580550-1c8d-5ed9-a254-344abf0c72d4
Feed Name: CyberScoop
Threat Score
OpenAI disclosed that a supply-chain attack tied to a North Korean-linked group (UNC1069) injected malicious code into Axios via a compromised maintainer; the malicious package executed in a GitHub signing workflow used by OpenAI for macOS apps, prompting OpenAI to treat a signing certificate as compromised, revoke and rotate it, and warn users to update affected macOS applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
