OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues

2026-03-09T07:24:08Zcf246ceab8c8c324f53698d8fda974d7c239371bcf46a3477d431fb9f094a65a
APTCISA-KEVCVERATactive-exploitationai-securityexploit-kitmalwarephishingsupply-chainvulnerabilities

What happened

Roundup of multiple cybersecurity developments: OpenAI launched Codex Security (research preview) after scanning ~1.2M commits and flagging 10,561 high-severity issues; Anthropic used Claude Opus 4.6 to find 22 Firefox vulnerabilities (14 high) fixed in Firefox 148; threat actors (Transparent Tribe, MuddyWater, China-linked groups, APT28/Silver Dragon, Dust Specter) and crimeware operations are actively using AI, new loaders/backdoors, and mass malware delivery (VOID#GEIST delivering XWorm/AsyncRAT/Xeno RAT; ClickFix campaign using Windows Terminal to deploy Lumma Stealer; fake Laravel Packag-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
cf246ceab8c8c324f53698d8fda974d7c239371bcf46a3477d431fb9f094a65a
Enrichment time
2026-03-09T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.