Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise
2026-03-31T07:24:08Z•ddb8d12121fe10fbc5f4402864e7cf8aa3758e63e4c1d7c919e784a780b77413
CareCloudCitrix NetScalerCodexDarkSwordEHREuropean CommissionGitHub tokensHuskeysLLM securityOpenAIPyPIRussian APTShinyHuntersStar BlizzardTeamPCPTelnyxaccess controlcritical vulnerability exploitation begun (Citrix)data theftedge securityhealthcare breachiOS exploitleast privilegesession hijackingsupply chain
What happened
This SecurityWeek feed aggregates multiple high-impact cybersecurity developments: researchers disclosed a vulnerability in OpenAI Codex that could have been used to compromise GitHub tokens; CareCloud is investigating a potential data breach affecting one of its EHR environments; and an identified trend (“silent drift”) shows LLM-generated policy code can inadvertently break least-privilege access controls. Separately, Russian APT Star Blizzard is using the DarkSword iOS exploit kit, the ShinyHunters group claims ~350GB stolen from European Commission cloud systems, and Iran-linked actors are
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- ddb8d12121fe10fbc5f4402864e7cf8aa3758e63e4c1d7c919e784a780b77413
- Enrichment time
- 2026-03-31T07:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.