Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

2026-03-31T07:24:08Zddb8d12121fe10fbc5f4402864e7cf8aa3758e63e4c1d7c919e784a780b77413
CareCloudCitrix NetScalerCodexDarkSwordEHREuropean CommissionGitHub tokensHuskeysLLM securityOpenAIPyPIRussian APTShinyHuntersStar BlizzardTeamPCPTelnyxaccess controlcritical vulnerability exploitation begun (Citrix)data theftedge securityhealthcare breachiOS exploitleast privilegesession hijackingsupply chain

What happened

This SecurityWeek feed aggregates multiple high-impact cybersecurity developments: researchers disclosed a vulnerability in OpenAI Codex that could have been used to compromise GitHub tokens; CareCloud is investigating a potential data breach affecting one of its EHR environments; and an identified trend (“silent drift”) shows LLM-generated policy code can inadvertently break least-privilege access controls. Separately, Russian APT Star Blizzard is using the DarkSword iOS exploit kit, the ShinyHunters group claims ~350GB stolen from European Commission cloud systems, and Iran-linked actors are

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
ddb8d12121fe10fbc5f4402864e7cf8aa3758e63e4c1d7c919e784a780b77413
Enrichment time
2026-03-31T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.