OpenAI Codex
Coverage of OpenAI Codex in the Nexus archive.
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers identified a critical security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allowing unauthenticated remote code execution. The vulnerability, CVE-2026-59726 (CVSS score: 10.0), affects versions before 3.16.3 and was codenamed RufRoot by Noma Security.
- At last, a good reason to buy an AI PC: Reining in runaway token bills
Gartner's Steve Kleynhans highlights AI PCs as a potential solution for enterprises to reduce cloud AI token costs, citing advances in small language models (SLMs) and hybrid strategies. The firm predicts 30% of enterprises will use AI PCs by 2029 and 70% of corporate PCs will support local AI workloads by 2030.
- A way to exclude sensitive files issue still open for OpenAI Codex
An issue regarding excluding sensitive files in OpenAI Codex remains unresolved. The problem is discussed in a GitHub issue and linked Hacker News comments, with 22 points and 16 discussions.
- New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
Cybersecurity researchers discovered a remote denial-of-service vulnerability, HTTP/2 Bomb, affecting major web servers including NGINX, Apache, IIS, Envoy, and Cloudflare. The exploit exists in default HTTP/2 configurations and was found by OpenAI Codex through chaining.
- OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Cybersecurity researchers revealed a malicious supply chain attack targeting OpenAI Codex users via the codexui-android npm package, which is promoted as a remote web UI and has over 29,000 weekly downloads. The package remains available for download despite the security risks it poses.