OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

2026-03-09T01:24:13Z2c55be8f2cc58f01e301a99993ec82532fc4248c6b139bc697b90399219f6906
AI securityAI-powered offenseAPT activityAnthropicCISA KEVCVE-2017-7921CVE-2026-20122CVE-2026-22719Lumma StealerMuddyWater (Seedworm)OpenAI Codex SecurityRATs (XWorm/AsyncRAT/Xeno)Transparent Tribeactive exploitationexploit kit (Coruna)law enforcement seizuresmalicious packagesmalware campaignsphishing-as-a-service takedownsupply chain compromisevulnerability research

What happened

A broad set of cybersecurity developments: AI is being used both to find flaws and to build malware—OpenAI’s new Codex Security scanned 1.2M commits and flagged 10,561 high-severity issues while threat actors (e.g., Transparent Tribe) and researchers (Anthropic using Claude Opus) used LLMs to discover or mass-produce vulnerabilities and implants. Multiple active campaigns and new malware families were reported (VOID#GEIST delivering XWorm/AsyncRAT/Xeno RAT; ClickFix campaign deploying Lumma Stealer; MuddyWater’s Dindoor backdoor; Dust Specter’s SPLITDROP/GHOSTFORM; APT28’s BadPaw/MeowMeow; APT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
2c55be8f2cc58f01e301a99993ec82532fc4248c6b139bc697b90399219f6906
Enrichment time
2026-03-09T01:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.