Luki w narzędziu OpenAI Codex pozwalają na ucieczkę z sandboxa. Szczegóły podatności Heapjack oraz Overpatch
Jeszcze do niedawna, mówiąc o wsparciu AI mieliśmy na myśli błyskawiczne generowanie podsumowań, przeprowadzanie analiz dokumentów źródłowych, wykonywanie tłumaczeń na niemal dowolny język oraz tworzenie prostych funkcji i skryptów pozwalających na automatyzację rutynowych zadań. Wraz z pojawieniem się agentów AI nastąpiła jednak prawdziwa rewolucja. TLDR: Sztuczna inteligencja przestała być jedynie...
#Aktualności #Codex #Heapjack #Openai #Overpatch #Rce #Sanbox
https://sekurak.pl/luki-w-narzedziu-openai-codex-pozwalaja-na-ucieczke-z-sandboxa-szczegoly-podatnosci-heapjack-oraz-overpatch/
#codex
23 posts · Last used 9d
Luki w narzędziu OpenAI Codex pozwalają na ucieczkę z sandboxa. Szczegóły podatności Heapjack oraz Overpatch https://sekurak.pl/luki-w-narzedziu-openai-codex-pozwalaja-na-ucieczke-z-sandboxa-szczegoly-podatnosci-heapjack-oraz-overpatch/ #Aktualnoci #Codex #Heapjack #Openai #Overpatch #Rce #Sanbox
Hmm. #Codex is down for me. Suddenly my Codex app's chat windows cannot connect to the back-end API.
OpenAI is building a personal AI agent to counter SpaceXAI's Grok Bot and Meta's Muse, hiring the OpenClaw creator to lead its Codex Bot effort.
#OpenAI #AIagents #GrokBot #MetaMuse #Codex #OpenClaw #TechNews
https://securityonline.info/openai-counter-grok-bot-muse/?utm_source=mastodon&utm_medium=jetpack_social
The Codex context mechanism redesign introduces persistent notes and history tools. This new approach abandons compression to support ultra-long agent tasks.
#Codex #ContextMechanism #AIAgents #TechNews
https://securityonline.info/codex-context-mechanism-redesign/?utm_source=mastodon&utm_medium=jetpack_social
Local LLM Arena #5
Pierwszy prawdziwy test GPT-OSS jako lokalnego agenta programistycznego przyniósł więcej informacji, niż się spodziewałem — tylko niekoniecznie o samym modelu.
Okazało się, że pierwsza wersja testu miała problem z izolacją środowiska Codex CLI. Do kontekstu lokalnego modelu trafiały informacje o wtyczkach i narzędziach, które nie miały nic wspólnego z zadaniem programistycznym.
Dlatego wyniku tego testu nie traktuję jako miarodajnego wyniku GPT-OSS.
Zacząłem więc poprawiać środowisko: czyste sesje, brak chmurowego fallbacku, izolacja hidden testów, kontrola retry, timeouty i dodatkowa diagnostyka.
I tutaj pojawił się kolejny problem.
Sam system testujący zrobił się zbyt skomplikowany.
Kolejne preflighty potrafiły zawieszać procesy na wiele godzin, a podczas ostatniej próby Antigravity doszedł do około 48 GB (?!?!?) zajętej pamięci na MacBooku Air M4 z 16 GB RAM.
System w końcu przestał odpowiadać i potrzebny był twardy restart.
Na szczęście właściwy Trial #2 nigdy nie został uruchomiony, a po restarcie Mac wrócił do normalnego stanu: 0 MB swapu i około 87% wolnej pamięci.
Wniosek jest prosty: nie ma sensu dokładać kolejnych warstw do wadliwego harnessu.
Teraz robię krok wstecz.
Codex ma przeprowadzić audyt całej obecnej infrastruktury i pomóc zaprojektować prostszą wersję V4.
Założenia są już inne:
– każdy proces ma twardy timeout,
– żadnego czekania godzinami,
– test ma własny niezależny System Guard,
– w razie problemów zatrzymywana jest tylko grupa procesów trialu,
– hidden testy są całkowicie poza zasięgiem modelu podczas kodowania,
– iCloud nie jest częścią krytycznej ścieżki,
– Antigravity ma tylko przygotować i uruchomić test, a nie czekać na niego godzinami.
Cel się nie zmienił.
Tym razem jednak najpierw trzeba mieć pewność, że sam test nie jest groźniejszy dla Maca niż model, który ma sprawdzać.
#LocalLLM #LLM #AI #AppleSilicon #MacBookAir #M4 #LMStudio #Codex #GPTOSS #Coding #OpenSourceAI
Holy... ich habe mir einen so genannten #macOS JXA #Backdoor Loader eingefangen. Gemeldet hat es vorhin #CleanMyMac. Ich hab es mal von #Codex analysieren lassen, und es hat mir den Verdacht bestätigt und einen Report erstellt.
—
Warnung: DigitStealer über die gefälschte „AppleLake“-AppWas ist es?
Der untersuchte JavaScript-Code ist eine persistente macOS-Backdoor aus der Malware-Familie DigitStealer. Er läuft als JavaScript for Automation (JXA) über osascript und ist stark verschleiert, damit Sicherheitsprogramme und Analysten ihn schwerer erkennen.
Eine konkrete Person oder Gruppe ist bislang nicht belastbar identifiziert. Jamf Threat Labs schreibt ausdrücklich, dass die Attribution dieser Variante unklar ist. Der Entwickler der echten DynamicLake-App hat damit nichts zu tun. Seine Software und Marke werden lediglich imitiert.
Was macht es?
Die untersuchte Datei ist vor allem die dauerhafte Fernsteuerung des Angriffs:
Sie ermittelt die Hardware-UUID des Macs und verwendet deren MD5-Hash als Gerätekennung.Sie kontaktiert alle 60 Sekunden fixyourallergywithus[.]com/api/poll.Sie verarbeitet Proof-of-Work-Aufgaben und Zugriffstoken des Servers.Sie lädt beliebige weitere Befehle oder Payloads nach.Diese werden unsichtbar als Bash, AppleScript oder JXA ausgeführt.Ein LaunchAgent startet die Backdoor bei jeder Anmeldung erneut und hält sie dauerhaft aktiv.
Die übrigen Stufen von DigitStealer stehlen laut Jamf unter anderem Browserdaten, Cookies, Passwörter, Keychain-Daten, Telegram-Sitzungen, Dokumente und Daten von Kryptowährungs-Wallets. Der hier untersuchte Code sorgt anschließend für dauerhaften Fernzugriff.
Wo kommt es her?
Die lokale Forensik ergab eine lückenlose Infektionskette vom 7. Februar 2026:
Ein YouTube-Video bewarb „Apple Lake“ als Dynamic-Island-App für macOS.Der Link führte zu applake[.]app.Von dort wurde AppleLake.dmg über Dropbox geladen.Das Image forderte dazu auf, Drag into Terminal.xyz im Terminal auszuführen.In genau derselben Sekunde wurden die JXA-Backdoor und ein LaunchAgent unter zufällig wirkenden Namen installiert.
Diese Verteilung ist kein Einzelfall. Eine Analyse der AppleLake-Kampagne verbindet applake.app, YouTube-Werbung und AppleLake.dmg direkt mit DigitStealer. Ein öffentliches AppleLake.dmg-Sample bei MalwareBazaar bestätigt die Malware-Verteilung unter diesem Namen. Auch die verwendete C2-Domain taucht in einer öffentlichen Falcon-Sandbox-Analyse auf.
Wie hängt alles zusammen?
YouTube-Werbung → gefälschte Website → AppleLake.dmg → Terminal-Dropper → Datendiebstahl + persistente JXA-Backdoor → Fernsteuerung über C2
Das sichtbare „AppleLake“-Programm ist nur der Köder. Der Terminal-Schritt umgeht die normale App-Prüfung und startet mehrere Schadcode-Stufen. Der Infostealer sammelt und überträgt Daten. Der LaunchAgent sorgt dafür, dass die Backdoor auch nach Neustarts weiterläuft und jederzeit neue Befehle empfangen kann.
Wer AppleLake.dmg oder eine angebliche macOS-App per „Drag into Terminal“ ausgeführt hat, sollte den Mac als kompromittiert betrachten. Nur die sichtbare Datei zu löschen reicht nicht. Sitzungen und Zugangsdaten sollten von einem sauberen Gerät aus widerrufen beziehungsweise geändert werden. Für eine verlässliche Bereinigung ist eine vollständige Neuinstallation von macOS die sicherste Option.
#macOS #Malware #DigitStealer #Infosec #Cybersecurity
Mein Tipp für alle, die #Claude Code, #Codex & Co. nutzen! 💡
Mit der nützlichen App #SessionWatcher hat man seinen Token-Verbrauch immer im Blick:
https://steigerlegal.ch/2026/07/25/sessionwatcher-ki-coding-app-macos
Caveat: Die App läuft unter #MacOS, aber wer solche KI-Coding-Dienste verwendet, wird in vielen Fällen ohnehin MacOS verwenden.
OpenAI admits GPT-5.6 deletes files in rare cases: a $HOME bug made its Full-Access agent wipe user folders. New guardrails and safer defaults are coming.
#OpenAI #GPT56 #AIAgents #DataLoss #Codex #AISafety
https://securityexpress.info/gpt-5-6-deletes-files/?utm_source=mastodon&utm_medium=jetpack_social
OpenAI trims the Codex context window from 372K to 272K and adds a system-prompt rule banning rm -rf $HOME after GPT-5.6 Sol wiped user home directories.
#Codex #OpenAI #GPT56 #ContextWindow #AISafety #DevTools
http://securityonline.info/codex-context-window/?utm_source=mastodon&utm_medium=jetpack_social
Windows Defender is flagging #Codex as malicious. "This program is dangerous and executes commands from an attacker."
The ironic part is I'm working on building a devcontainer module for https://github.com/franklesniak/copilot-repo-template/ -- to make it easy to sandbox coding agents. I guess I'll work from Codex on the web...
Encouraging agents to be prolific writers and readers of trace logs is a strategy that keeps paying dividends.
https://blog.jonudell.net/2026/07/08/dont-infer-behavior-from-code-observe-it-in-logs/
#claude_code #codex #logging #debugging
@Matthew_Berman on YT!
GPT-5.6 is FINALLY HERE (WOAH)
#GPT5.6 #CODEX #AI #OPENAI
...5 days for an Excel Clone 🤔
https://www.youtube.com/watch?v=mD1F5DsC5tc
7/9/2026
GPT-5.6 is FINALLY HERE (WOAH)
The recent Claude Code credit reset intensifies the AI race with OpenAI, allowing developers extended access to the powerful Claude Fable 5 model.
#ClaudeCode #OpenAI #Codex #ArtificialIntelligence #TechNews
https://securityonline.info/claude-code-credit-reset/?utm_source=mastodon&utm_medium=jetpack_social
Escoffier Labs late night special: Codex Spark scouts.
Brigade can now fan out read-only Codex Spark scouts across a repo.
First eval: 6 shards, 164s, 9 findings, 2 verified fixes.
Also finally putting my Codex Spark quota to work instead of letting it sit there unused every week.
Upgrade to Brigade 0.19.0:
https://github.com/escoffier-labs/brigade/releases/tag/v0.19.0
#Brigade #Codex #OpenSource #AI
BBC News | OpenAI tells ChatGPT models to stop talking about goblins
AI generated summary, Read the full article for complete information.
OpenAI has instructed its AI tools—including ChatGPT and the coding assistant Codex—to stop mentioning goblins, gremlins and other mythical creatures after a sharp rise in such references was detected following the launch of GPT‑5.1; the company traced the issue to a “nerdy personality” that unintentionally rewarded goblin mentions, causing a 175% increase in goblin references and a 52% rise in gremlin mentions, and responded by adding explicit instructions to avoid these terms unless absolutely relevant. This episode underscores the broader challenge of fine‑tuning chatbots for more personable, engaging dialogue, where attempts to add character can create odd linguistic quirks and potentially affect accuracy.
Read more: https://www.bbc.com/news/articles/c5y9wen5z8ro?at_medium=RSS&at_campaign=rss
#OpenAI #ChatGPT #GPT51 #Codex #OxfordInternetInstitute #
openai codex windows için masaüstü uygulama yayınladı. Dün bir deneme yaptım. Aktif bir vscode kullanıcısı için bir ekstrası olmadığını söyleyebiilirim. Neyse, asıl söylemek istediğim: Denemede hayatım boyunca yapmak isteyip nasıl yapacağımı bilemediğim bir uygulamayı yarım saat içinde, benim hayal edemeyeceğim derecede gelişmiş halini yayınladı. Bir fikriniz varsa, "bu haliyle başarılı sonuç üretmez" diye düşünmeyin, codex kendisi fikri geliştiriyor ve neden kendi önerdiği fikrin daha iyi olduğu hakkında yazılı bir çıktı üretiyor. #codex #openai #vscode

