MEDIUMSupply Chain
Global

OpenAI’s Mac apps need updates thanks to the Axios hack

·Source: CyberScoop

Updated:

Executive Summary

The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not impacted. The post OpenAI’s Mac apps need updates thanks to the Axios hack appeared first on CyberScoop .

Analysis

The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not impacted. The post OpenAI’s Mac apps need updates thanks to the Axios hack appeared first on CyberScoop .
Source Attribution

Originally published by CyberScoop on Apr 13, 2026.

Related Threats

LOWSupply Chain

AI adoption and business acceleration are changing the expectations of technology risk management

As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evolved faster than the programs built to govern it. The result is a widening gap between the pace of transformation and the

CSO Online
MEDIUMSupply Chain

What Is Grounding? Why AI Coding Assistants Need Better Intelligence

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/what-is-grounding-why-ai-coding-assistants-need-better-intelligence" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_what_is_grounding.jpg" alt="Image with an icon of a human head at center with lightning bolt in it and the head is surrounded by gear icons." class="hs-featured-imag

Sonatype (Maven/npm)
LOWSupply Chain

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -

The Hacker News