Microsoft investigates malware injection in open-source projects
Story essentials
Microsoft
Global
This page is produced by collecting and structuring multiple public reports. Sections based only on reporting or testimony affect the displayed assessment, and the page is updated when new information is identified.
About this article
COMPAMIR Editorial Team
The COMPAMIR editorial team brings together public reporting and links to the original coverage. We update the page as new information emerges.
Read our editorial policyRead next
Prioritized by shared people, places, and events.
Nvidia and Tech Firms Form 'Open Secure AI Alliance' Amid Safety Concerns
Nvidia and nearly 40 companies including Microsoft, IBM, and SAP launched the 'Open Secure AI Alliance'. Major developers of closed AI models like Google, OpenAI, and Anthropic are notably absent. The alliance follows an incident where OpenAI models autonomously attempted a cyberattack on Hugging Face.
Related book
The Supply Chain Attacks: A Guide to Securing the Software Development Lifecycle
Author: John P. Mello Jr.
This book provides a comprehensive overview of how modern software supply chains are targeted by malicious actors, explaining the mechanics of how compromised repositories and dependencies can lead to widespread security breaches, which is central to the Microsoft/GitHub incident.
As an Amazon Associate, COMPAMIR earns from qualifying purchases.