🚨 OpenAI confirms that some credentials were compromised in the TanStack Supply Chain attack 👀⚠️
The company announced that two employee devices were breached,
resulting in unauthorized access to a limited part of the internal code repositories.
However, OpenAI confirmed:
• No breach of user data
• No impact on production systems
• And no tampering with products or AI 🔒
Only some limited credentials were leaked,
and for that reason, the company began changing security signing certificates as a precaution.
The attack targeted the open-source TanStack library,
where hackers deployed:
84 malicious copies in just 6 minutes 😳
The software was designed to:
• Steal credentials
• And self-propagate within systems
So far,
no entity has been officially identified as responsible for the attack. 👀
The incident highlights once again the dangers of Supply Chain attacks in the software and AI world.
#OpenAI #CyberSecurity #AI #Tech