OpenAI confirms security breach in TanStack supply chain attack

2026-05-14T19:23:31Zd0d18eb05da27c5ab5ba2370256ab8709187bf0bfce2bed6156e19369474aac1
BitLockerCVE-2026-46300Dell SupportAssist BSODs','West Pharmaceutical','ransomware/dataEximFragnesiaGreenPlasmaKongTukeLinux kernelMicrosoft EdgeMicrosoft TeamsNGINXOpenAIPwn2OwnPyPITanStackWindows 11YellowKeycargo-theftcode-signingcyber-enabled cargo crimedenial-of-servicenpmremote-code-executionsupply-chainzero-day

What happened

A batch of high-impact security incidents and vulnerabilities was reported: OpenAI confirmed two employee devices were breached via the widespread TanStack supply‑chain attack (affecting npm/PyPI packages) prompting code‑signing certificate rotations; Pwn2Own Berlin yielded 24 unique zero‑days (including Windows 11 and Microsoft Edge exploits); an 18‑year‑old NGINX flaw can cause DoS and possible RCE; a critical Exim configuration‑specific RCE was disclosed; a new high‑severity Linux kernel privilege escalation (“Fragnesia”, tracked as CVE-2026-46300) allows local root; BitLocker bypass and P‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d0d18eb05da27c5ab5ba2370256ab8709187bf0bfce2bed6156e19369474aac1
Enrichment time
2026-05-14T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.