October 09, 2026 06:28 am (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
‘Bold and inventive’: Canadian poet Anne Carson wins 2026 Nobel Prize in Literature | ‘Attempt to destabilise world’s largest democracy’: 42 retired judges rally behind Gyanesh Kumar over ‘vote chori’ row | ‘Vote chor, gaddi chod’: Dhruv Rathee, Prakash Raj join Bengaluru protest against Gyanesh Kumar | India condemns Houthi attacks on Saudi airports, calls targeting of civilian infrastructure unacceptable | Dalal Street bloodbath: Investors lose Rs. 8 lakh crore as Sensex crashes over 1,000 points | Amazon layoffs hit India, US and UK: Fresh job cuts rock e-commerce giant amid festive shopping season | Bollywood mourns Nana Patekar: Anupam Kher, Akshay Kumar, Jr NTR, Suniel Shetty pay emotional tributes | ‘He was never wavering while expressing his opinions’: PM Modi mourns Nana Patekar | Nana Patekar dies at 75: Veteran actor suffers cardiac arrest at Goa home | RBI shocks borrowers with first repo rate hike since 2023; rates raised to 5.50%
OpenAI
OpenAI logo. Photo: Unsplash

OpenAI identified security issue. Know all details

| @indiablooms | Apr 11, 2026, at 05:09 pm

AI major OpenAI has disclosed a recent security issue involving a third-party developer library, Axios, as part of a broader industry-wide software supply chain attack.

In an official statement, OpenAI said, “We recently identified a security issue involving a third-party developer tool, Axios, that was part of a widely reported, broader industry incident.”

The company emphasized that, as a precautionary measure, it is taking steps to strengthen the integrity of its macOS application certification process to ensure that only legitimate OpenAI apps are recognized.

Reassuring users, OpenAI stated that there is no evidence suggesting that user data was accessed, internal systems or intellectual property were compromised, or any software was altered.

What Happened?

According to the company, the incident dates back to March 31, 2026 (UTC), when Axios—widely used in software development—was compromised in a supply chain attack.

During this period, a GitHub Actions workflow used by OpenAI in its macOS app-signing process inadvertently downloaded and executed a malicious version of Axios (version 1.14.1). This workflow had access to sensitive signing infrastructure, including certificates and notarization materials used for authenticating macOS applications such as ChatGPT Desktop, Codex, Codex CLI, and Atlas.

These certificates are critical for verifying that applications originate from a legitimate developer—in this case, OpenAI.

Risk Assessment and Response

OpenAI noted that its internal analysis indicates the signing certificate was likely not exfiltrated by the malicious payload. This assessment is based on factors such as the timing of the payload execution, the sequencing of the workflow, and additional safeguards in place.

However, exercising caution, the company has decided to treat the certificate as potentially compromised. As a result, it is revoking and rotating the affected certificates.

Steps for Users

OpenAI announced that it is updating its security certificates, which will require all macOS users to update their OpenAI applications to the latest versions.

“This helps prevent any risk—however unlikely—of someone attempting to distribute a fake app that appears to be from OpenAI,” the company said.

Additionally, OpenAI confirmed that starting May 8, 2026, older versions of its macOS desktop applications will no longer receive updates or support and may stop functioning altogether.

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.