OpenAI confirms security breach in TanStack supply chain attack
2026-05-14T19:23:31Z•d0d18eb05da27c5ab5ba2370256ab8709187bf0bfce2bed6156e19369474aac1
BitLockerCVE-2026-46300Dell SupportAssist BSODs','West Pharmaceutical','ransomware/dataEximFragnesiaGreenPlasmaKongTukeLinux kernelMicrosoft EdgeMicrosoft TeamsNGINXOpenAIPwn2OwnPyPITanStackWindows 11YellowKeycargo-theftcode-signingcyber-enabled cargo crimedenial-of-servicenpmremote-code-executionsupply-chainzero-day
What happened
A batch of high-impact security incidents and vulnerabilities was reported: OpenAI confirmed two employee devices were breached via the widespread TanStack supply‑chain attack (affecting npm/PyPI packages) prompting code‑signing certificate rotations; Pwn2Own Berlin yielded 24 unique zero‑days (including Windows 11 and Microsoft Edge exploits); an 18‑year‑old NGINX flaw can cause DoS and possible RCE; a critical Exim configuration‑specific RCE was disclosed; a new high‑severity Linux kernel privilege escalation (“Fragnesia”, tracked as CVE-2026-46300) allows local root; BitLocker bypass and P‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d0d18eb05da27c5ab5ba2370256ab8709187bf0bfce2bed6156e19369474aac1
- Enrichment time
- 2026-05-14T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.