OpenAI Rotates Certificates After TanStack Supply Chain Attack Hits Employee Devices

https://informationsecuritybuzz.com/wp-content/uploads/OpenAI-rotates-certificates.jpg

OpenAI has confirmed that two employee devices were compromised in the recent TanStack npm supply chain attack, prompting the company to rotate code-signing certificates and require macOS users to update their applications by 12 June.

In a security advisory published this week, the company said it found no evidence that customer data, production systems, or intellectual property were accessed or altered during the incident.

The compromise is related to a larger campaign known as “Mini Shai-Hulud,” which is an example of a software supply chain attack targeting commonly used packages from npm and PyPI repositories. The TanStack web application development framework, one of the many frameworks impacted by the attack, was exploited through compromised GitHub Actions caches where malicious versions of the npm package were made available.

The organization stated that the malware’s behavior was consistent with that described in public reports on this attack campaign. This involved the theft...

Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE

Read more

https://images.axios.com/Kxyg8eq2uv6XV27_YrWwla5Nva0=/0x438:5363x3455/1366x768/2026/06/24/1782339919203.jpeg

Warp, a startup using AI to automate payroll compliance and employee management, raised a $60M Series B led by Battery, bringing its total funding to $85M

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.

http://www.techmeme.com/img/techmeme_sq328.png

Utah-based ecommerce tech company Redo raised an $81M Series B at a $1.25B valuation led by Smash Capital, with participation from Pelion and Cervin

Sponsor Posts Fast, affordable law for startups — Soxton automates startup legal so founders can move faster and sleep better. We handle incorporation, advisor, employment and commercial contracts. Join the waitlist for early access! Stop vibe coding analytics — Equals AI turns questions about your business into auditable spreadsheet models and dashboards.