OpenAI identifies security issue involving third-party tool, says user data was not accessed

OpenAI identifies security issue involving third-party tool, says user data was not accessed


Samuel Boivin | Nurphoto | Getty Images

OpenAI said on Friday it had identified a security issue involving a third-party developer tool called Axios and is taking steps to protect the process that certifies its macOS applications are legitimate OpenAI apps.

The ChatGPT maker said it found no evidence that its user data was accessed, that its systems or intellectual property was compromised, or that its software was altered.

* The company said it is updating its security certifications, requiring all macOS users to update their OpenAI apps to the latest versions to help prevent any risk of someone attempting to distribute a fake app.

* According to OpenAI, Axios, a widely used third-party developer library, was compromised on March 31, as part of a broader software supply chain attack by actors believed to be linked to North Korea.

* This attack led a GitHub Actions workflow used by OpenAI to download and execute a ‘malicious’ version of Axios. This workflow had access to a certificate and notarization material used for signing macOS applications, including ChatGPT Desktop, Codex, Codex-cli, and Atlas.

* OpenAI said its analysis of the incident concluded that the signing certificate present in this workflow was likely not successfully exfiltrated by the ‘malicious’ payload.

* Effective May 8, older versions of OpenAI’s macOS desktop apps will no longer receive updates or support, and may not be functional, the ChatGPT maker said.

* Passwords and OpenAI API keys were not affected by the third-party security issue, the company said, adding that the root cause of the security incident was a misconfiguration in the GitHub Actions workflow, which has been addressed.

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.



Source

How to help kids form healthy relationships with money: They ‘end up in much better financial shape’ as adults, psychologist says
World

How to help kids form healthy relationships with money: They ‘end up in much better financial shape’ as adults, psychologist says

As parents contend with rising costs and an overall tighter economic climate, more of them are using those challenges as an opportunity to have frank talks with their kids about money, according to a recent survey. Honest conversations — including telling your kids “no” when they ask you to buy something, and explaining why — […]

Read More
Berkshire electric utility’s court win could save it billions
World

Berkshire electric utility’s court win could save it billions

(This is the Warren Buffett Watch newsletter, news and analysis on all things Warren Buffett and Berkshire Hathaway. You can sign up here to receive it every Friday evening in your inbox.) PacifiCorp court win could reduce wildfire damages by $1B or more  An Oregon Court of Appeals ruling this week accepted PacifiCorp’s argument the judge in a 2023 trial mistakenly […]

Read More
Cathay Pacific to cut flights from mid-May to end-June as jet fuel prices surge
World

Cathay Pacific to cut flights from mid-May to end-June as jet fuel prices surge

A Cathay Pacific Airbus A350 aircraft at Kingsford Smith Airport on August 18, 2021 in Sydney, Australia. Cathay Pacific Airways Ltd., is the flag carrier of Hong Kong with its main hub being at Hong Kong International Airport. James D. Morgan | Getty Images News | Getty Images Cathay Pacific Airways said on Saturday it […]

Read More