OpenAI Devices Hacked, Ozempic Supplier Offline & Change Healthcare Lawsuit

OpenAI Devices Hacked, Ozempic Supplier Offline & Change Healthcare Lawsuit

May 19, 2026 · 45 min

About this episode

The episode discusses three significant cyber incidents highlighting the risks of third-party trust in business.

A poisoned software package compromised OpenAI employee devices before security teams could stop it. The company behind critical Ozempic injection components has been offline for weeks after a ransomware attack. And Change Healthcare is now facing another major lawsuit tied to the 2024 breach that crippled healthcare payments nationwide. Three stories. One message: Your business is now exposed to companies you don't control. On this episode of Security Squawk, Bryan Hornung, Randy Bryan, and Reginald Andre break down three cyber incidents that reveal how third-party trust has become one of the biggest operational risks in business today. This Week's Cybersecurity Breakdown 1. OpenAI, TanStack & the npm Supply Chain Worm A software supply chain attack spread through trusted developer ecosystems at massive speed: 42 npm packages poisoned in six minutes Malware stole GitHub tokens, AWS credentials, and CI/CD secrets OpenAI confirmed two employee devices were compromised ChatGPT Desktop, Codex App, Codex CLI, and Atlas certificates rotated Demonstrates how modern attacks now spread through trusted development infrastructure 2. West Pharmaceutical Ransomware Attack A cyberattack…

More episodes of Security Squawk - The Business of Cybersecurity

Explore listener stats, chart rankings, contacts and more on the Security Squawk - The Business of Cybersecurity podcast page.