Tech News
← Home  ·  All topics

Openai Codex

9 GoKawiil briefs on this topic

OpenAI Codex sandbox flaws let attackers execute code on developer machines

Security researchers at Accomplish AI discovered two ways to break out of the sandbox that isolates OpenAI's Codex coding agent from a user's system. The worse of the two, dubbed Heapjack, let a malicious repository trigger unsandboxed code execution on a victim's machine simply by having Codex answer a question about that repo's code, with no approval prompt or visible warning. Both bugs were reported to OpenAI on August 12 and patched within eight days.

OpenAI details rollout steps for GPT-6 Astra across ChatGPT tiers

OpenAI is gradually enabling GPT-6 Astra for Pro, Business and Enterprise users, who can find it labeled as GPT-6 Pro in the model picker rather than under the Astra name. Plus subscribers get access through the Work mode in web, mobile or desktop apps, while Codex users need CLI version 0.153.0 or later. Availability varies by platform, and Enterprise access also depends on workspace permissions.

AI-driven exploit campaign breaches 395 organizations via PaperCut flaws

GreyNoise reports that a likely Russian-speaking threat actor deployed hundreds of AI agents using OpenAI's Codex and DeepSeek models to build and launch exploits against two PaperCut NG/MF vulnerabilities. The campaign, which began August 31, compromised at least 440 servers across 395 organizations in 48 countries, mostly in education, with credentials stolen from 280 victims and admin access gained at 12 organizations.

OpenAI accused of scraping Codex sessions to claim credit on Navier-Stokes research

NYU researcher Tristan Buckmaster says OpenAI touted a breakthrough on the Navier-Stokes Millennium Prize problem that closely mirrors a year-long personal project he ran with Anthropic's Levent Alpöge using Claude and Codex as assistants. Buckmaster alleges OpenAI accessed his private Codex session logs and that the company issued threats regarding his career after he raised concerns, though he says the AI-generated proof itself was low quality, calling it 'AI slop'.

AI-assisted proof of 51-year-old Spherical Hadwiger Conjecture published by Hunan University researchers

Mathematicians Wang and Wu of Hunan University released a preprint proving the Spherical Hadwiger Conjecture, an integral-geometry problem unsolved since 1974, using OpenAI Codex to help develop proof details, spot gaps, and draft the manuscript. The authors say they verified all AI-generated mathematical content themselves and take full responsibility for the final result, following disclosure practices similar to the Leiden Declaration guidelines for AI use in research.

AISLE's AI tool finds six curl CVEs days after OpenAI and Anthropic tools report none

After curl founder Daniel Stenberg ran OpenAI's Codex Security and Anthropic's Mythos against the widely-used curl codebase and got zero findings, AISLE's autonomous AI system produced 29 vulnerability reports. Six of those were validated by curl's security team and assigned CVE identifiers, all rated Low severity, and fixed in the newly released curl 8.22.0.

OpenAI's Codex desktop app quietly ships a bundled LibreOffice install

A user inspecting disk usage discovered that OpenAI's Codex desktop app, now rebranded as part of ChatGPT, stores a 1.7GB cache folder containing full Python and Node.js runtimes alongside native binaries for Poppler, git, and the LibreOffice office suite. Accompanying 'skills' files instruct Codex on how to locate and invoke these bundled tools when handling document-related tasks.

OpenAI Testing 'Persistent Mode' for Codex Coding Agent

OpenAI is developing a new 'Persistent mode' for its Codex AI coding agent, spotted in code changes to the command-line tool's public repository. Unlike current settings that stop after minutes or hours, this mode would let Codex keep working on a task until manually stopped, or 'put to sleep.' An OpenAI spokesperson confirmed the feature is being tested but said there are no immediate plans for a public launch.

OpenAI reinstates five-hour usage caps for ChatGPT Plus on Work and Codex

OpenAI is bringing back five-hour usage limits for ChatGPT Plus subscribers using ChatGPT Work and Codex, starting August 25, after temporarily lifting them post-GPT-5.6 launch. Plus users will now draw from their weekly quota in five-hour blocks rather than using it freely, while ChatGPT Pro subscribers remain unaffected for now.