OpenAI Launches Codex Security in the US, Scans Over 1.2 Million Code Commits to Uncover Tens of Thousands of Critical Vulnerabilities
2026-03-09 11:15
Favorite

Wedoany.com Report on 9th, Recently, US artificial intelligence company OpenAI recently launched Codex Security, an AI-powered security agent specifically designed to detect and validate code vulnerabilities and provide remediation suggestions. The tool is now available in a research preview to ChatGPT Pro, Enterprise, Business, and Education customers via the Codex web interface and will be free to use next month.

During a recent 30-day test, Codex Security scanned over 1.2 million commits from external code repositories, identifying 792 critical issues and 10,561 high-risk vulnerabilities. These vulnerabilities involved multiple open-source projects such as OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP, and Chromium, including specific cases like CVE-2026-24881 and CVE-2026-24882 for GnuPG, and CVE-2025-32988 and CVE-2025-32989 for GnuTLS.

OpenAI stated that Codex Security is based on an evolved version of Aardvark and was launched as a private beta in October 2025, aiming to help developers and security teams handle security vulnerabilities at scale. The agent leverages the reasoning capabilities of cutting-edge models combined with an automated verification mechanism to reduce the risk of false positives and provide actionable fixes. The company said: "It builds deep contextual understanding of projects, identifies complex vulnerabilities that other tools might miss, and presents high-confidence findings and remediation suggestions, thereby enhancing system security and reducing noise from irrelevant errors."

According to OpenAI, Codex Security's workflow consists of three steps: first, analyzing the codebase to understand the system structure and security-relevant parts, generating an editable threat model; second, identifying and categorizing vulnerabilities based on system context, validating their effectiveness in a sandbox environment; and finally, proposing remediation solutions that match system behavior to reduce regression issues and simplify review and deployment. Continuous scanning shows the tool's precision has improved, with the false positive rate dropping by over 50% across all codebases.

In a statement shared with The Hacker News, OpenAI emphasized that Codex Security improves the signal-to-noise ratio by validating findings based on system context. The company added: "When configured with custom environments, Codex Security can directly validate potential issues within the running system. This deep verification further reduces false positives and provides security teams with a clearer remediation path." Previously, Anthropic also launched a similar tool, Claude Code Security, for scanning codebase vulnerabilities and suggesting patches.

Related Recommendations
Microsoft Revises Partnership Agreement with OpenAI: License Changed to Non-Exclusive, Revenue Sharing Terminated, Azure Priority Rights Maintained
2026-04-28
TSMC's Hou Yongqing Stated That to Meet AI Computing Demands, the Company Is Accelerating Capacity Expansion at "Double Speed," With 2nm First-Year Output Expected to Be 45% Higher Than 3nm at the Same Stage
2026-04-28
Qwen App Launches Gray-Scale Test of Alibaba’s Video Model HappyHorse, Supporting 15-Second Multi-View Narrative and 1080P Super-Resolution Output
2026-04-28
South Korea's Ministry of Science and ICT and Google DeepMind Sign AI Cooperation MOU to Jointly Advance the K-Moonshot National Innovation Project
2026-04-28
Embodied AI Company Galactic Dynamics Completes Over $200 Million in New Funding, Led by SF Express, With Batch Delivery of Thousands of Robots Underway
2026-04-28
Baidu Library and Baidu Netdisk Jointly Release the General Agent GenFlow 4.0, With Monthly Active Users Exceeding 100 Million and Monthly Task Delivery Reaching 200 Million
2026-04-28
Samsung Heavy Industries Signs MOU with M3 for Joint Development of Floating Data Centers to Meet Hyperscale and AI Computing Demands
2026-04-28
Lightmatter Appoints Roy Kim as Vice President of Products to Accelerate Mass Deployment of Photonic Interconnect Platform
2026-04-28
IQM to Deploy First Enterprise-Purchased Quantum Computer in Japan
2026-04-28
Australia's Quantum Clock TEMPO Successfully Enters Orbit, Achieving Timing Precision Ten Times Greater than Global Navigation Satellite Systems
2026-04-28