OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
2026-03-09T01:24:13Z•2c55be8f2cc58f01e301a99993ec82532fc4248c6b139bc697b90399219f6906
AI securityAI-powered offenseAPT activityAnthropicCISA KEVCVE-2017-7921CVE-2026-20122CVE-2026-22719Lumma StealerMuddyWater (Seedworm)OpenAI Codex SecurityRATs (XWorm/AsyncRAT/Xeno)Transparent Tribeactive exploitationexploit kit (Coruna)law enforcement seizuresmalicious packagesmalware campaignsphishing-as-a-service takedownsupply chain compromisevulnerability research
What happened
A broad set of cybersecurity developments: AI is being used both to find flaws and to build malware—OpenAI’s new Codex Security scanned 1.2M commits and flagged 10,561 high-severity issues while threat actors (e.g., Transparent Tribe) and researchers (Anthropic using Claude Opus) used LLMs to discover or mass-produce vulnerabilities and implants. Multiple active campaigns and new malware families were reported (VOID#GEIST delivering XWorm/AsyncRAT/Xeno RAT; ClickFix campaign deploying Lumma Stealer; MuddyWater’s Dindoor backdoor; Dust Specter’s SPLITDROP/GHOSTFORM; APT28’s BadPaw/MeowMeow; APT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2c55be8f2cc58f01e301a99993ec82532fc4248c6b139bc697b90399219f6906
- Enrichment time
- 2026-03-09T01:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.