LIVE FEED
FIRST LOOK Google Chrome Shifts to Two-Week Release Cycle for Faster Security Patches // FIRST LOOK Trail of Bits Ships Coop: Isolated VMs for Claude Code and Codex // CRITICAL CVE-2026-81578: PaperCut Exploited by AI Agents at Scale // FIRST LOOK arXiv Research Introduces Self-Evolving Procedural Graphs for LLM Agents // HIGH Chinese AI Firms Accused of Distilling OpenAI and Anthropic Models // HIGH Workflow Identity Hijacking Targets Enterprise AI Data Access // CRITICAL AI-Accelerated WeChat Zero-Click Worm Spreads via RCE // FIRST LOOK Microsoft Uses AI to Ship Record 974-Vulnerability Patch Batch // FIRST LOOK Meta Launches Muse Personal AI Agent with Secure VM Isolation // CRITICAL ChatGPT Cross-Account Data Leakage via Sandbox Channel //
TanStack Supply Chain Attack Exposes OpenAI Keys

TanStack Supply Chain Attack Exposes OpenAI Keys

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 The Hacker News

A supply chain attack targeting TanStack via the Mini Shai-Hulud malware compromised two OpenAI employee devices, exposing internal source code repositories and code-signing certificates for macOS, iOS, and Windows apps. While no user data or production systems were breached, OpenAI was forced to revoke and reissue signing certificates, requiring macOS users to update ChatGPT Desktop, Codex, and Atlas apps before June 12, 2026. The incident marks OpenAI's second certificate rotation in two months and is part of a broader campaign by threat actor TeamPCP targeting major AI and open-source ecosystems.

Axios npm Library Compromised in Supply Chain Attack

Axios npm Library Compromised in Supply Chain Attack

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 The Hacker News

A North Korean threat group (UNC1069) compromised the popular npm Axios library via a supply chain attack, injecting a backdoor (WAVESHAPER.V2) into two poisoned versions that were inadvertently downloaded by OpenAI's macOS app-signing GitHub Actions workflow. Although OpenAI found no evidence of certificate exfiltration or user data compromise, the incident exposed the signing credentials for ChatGPT Desktop, Codex, Codex CLI, and Atlas, prompting certificate revocation and mandatory app updates by May 8, 2026. The attack highlights the acute risk of software supply chain compromises against AI product delivery pipelines.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.