Cyber Security News

OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning

OpenAI has expanded its Codex platform with Codex Security Cloud, a cloud-hosted application security feature that continuously analyzes GitHub repositories, investigates potential vulnerabilities, and prepares remediation patches for human review.

Announced as part of the company’s latest Codex updates, this service is designed to operate security workflows beyond a developer’s local machine. It can run full repository assessments on demand, on a schedule, or as new commits are made, allowing security analysis to continue while developers are offline.

OpenAI Codex Security Cloud

Codex Security Cloud connects to GitHub repositories to create a threat model that reflects the application’s architecture and exposure. This model includes attacker entry points, trust boundaries, sensitive data, and critical code paths. Teams can inspect and modify this model to align it with their deployment environment.

Unlike traditional signature-based scanners or fuzzing tools, OpenAI claims that Codex Security employs language-model reasoning, tool usage, test-time computation, and large-context analysis to examine potential attack paths.

When it identifies a suspected vulnerability, the service attempts to validate the issue in an isolated environment before marking it as a finding.

This validation step aims to reduce duplicate and low-confidence alerts, which are persistent challenges for AppSec teams operating at scale. Codex Security Cloud also investigates findings, removes duplicates, and prepares proposed fixes in the cloud for developer review.

A prominent feature of this update is the default access to OpenAI’s Daybreak Blue cyber-capable models within Codex Security Cloud. Previously, accessing advanced cyber-focused capabilities required a separate application process.

This bundled access specifically applies within the Cloud product and does not extend automatically to other Codex Security products or OpenAI’s API.

OpenAI describes Daybreak as a governed cybersecurity stack designed for authorized defensive activities, including secure software development, vulnerability discovery, validation, remediation, incident response, and authorized security testing.

The platform is built to keep significant actions under human control through monitoring, scope restrictions, and review processes.

Despite its automated analysis and patch-generation capabilities, Codex Security Cloud does not automatically modify source code. Instead, it suggests a patch that can be converted into a pull request, which developers and security teams must review and approve as part of their standard engineering workflow.

This approach matters for organizations concerned that AI-generated fixes could introduce regressions, insecure logic, or environment-specific failures. OpenAI recommends that teams examine generated patch pull requests through their standard code-review process and utilize Codex Code Review to assist in assessing proposed security fixes.

Codex Security is currently available as a research preview for ChatGPT Pro, Business, Enterprise, and Edu customers. It can be accessed as a plugin through Codex desktop and web environments.

For Enterprise and Edu users, administrators can manage access through workspace permissions and role-based access controls. Organizations can restrict usage to specific roles or SCIM-synchronized groups, while separate permissions determine who can configure scans.

OpenAI’s initiative signifies a stronger commitment to agent-driven secure development workflows, where repository-wide analysis, commit monitoring, validation, and patch preparation operate continuously while leaving final remediation decisions to human defenders.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago