Researchers escape OpenAI Codex sandbox to run commands on host

2026-09-20T13:23:22Z•b5a39b8220f3dd5656674ce0b1ac6dd1cbb5aa863c7c54bd3616a79ec8b8e7ee
AI securityAndroid malwareCheck PointGitHub supply chainMicrosoft 365Microsoft securityNorth KoreaOpenAI CodexRapuncelRatHatWaterPlumbrowser agent hijackingcryptocurrency theftdata breachinfostealermalicious browser extensionsprivacyprivilege escalationprompt injectionransomwareremote code executionsandbox escape

What happened

A BleepingComputer security feed covering significant September 2026 developments, including OpenAI Codex sandbox escapes enabling host command execution, malicious extensions hijacking AI browser agents, a North Korean campaign compromising at least 30,000 devices and stealing cryptocurrency, large-scale data theft from Gyazo, malware distribution through fake GitHub repositories, critical Check Point root-level code execution, and new AI-assisted Android malware. The feed also includes security advisories, product fixes, privacy concerns, and defensive guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b5a39b8220f3dd5656674ce0b1ac6dd1cbb5aa863c7c54bd3616a79ec8b8e7ee
Enrichment time
2026-09-20T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.