Security Roundup: OpenAI Open Sources Codex Security CLI, AWS Pins NPM Attacks on North Korea, Anthropic Mythos Cracks Crypto
ID: 1d86e11c-5432-59de-92b9-63df1826e0d7
STIX ID: report--1d86e11c-5432-59de-92b9-63df1826e0d7
Feed Name: CosmicBytez Labs
Three major developments: OpenAI quietly released an open-source Codex Security CLI whose scanner engine remains restricted to enterprise customers; Amazon (AWS) attributed large npm supply-chain compromises (notably debug, chalk, axios) with malicious postinstall payloads to North Korean actor Sapphire Sleet, affecting downstream environments at large scale; and Anthropic's restricted Mythos model autonomously discovered and in some cases exploited thousands of OSS vulnerabilities (including a FreeBSD RCE and wolfSSL TLS certificate forgery) and produced advanced cryptographic attacks, highlighting broad risk from AI-accelerated vulnerability discovery and state-level supply-chain operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
