< ciso
brief />
Tag Banner

All news with #openai tag

323 articles · page 8 of 17

Fraudulent OpenAI organization invites target security firms

🔔 Push Security discovered a campaign where attackers create fraudulent OpenAI tenants impersonating real companies and send legitimate-looking invites to employees. The invites originate from OpenAI notification addresses, pass authentication checks, and assign recipients Owner privileges within the fake organization. Attackers used Gmail accounts to pose as company executives and even attached a billing card to the tenant, likely to reduce suspicion. Push Security warns employees could be tricked into submitting sensitive data into the workspace and advises verification and monitoring of SaaS memberships.
read more →

OpenAI expands Daybreak with GPT-5.5-Cyber release

🔒 OpenAI has expanded its Daybreak cyber-defense program, advancing patch automation with the full release of GPT-5.5-Cyber, updates to Codex Security, and a new open-source patching initiative. Access to the model is limited to verified defenders and paired with enhanced monitoring. OpenAI reports improved vulnerability reproduction and exploit-writing scores, while emphasizing human oversight and partnerships with vendors and governments.
read more →

OpenAI launches AI-driven open-source vulnerability program

🔒 OpenAI has teamed with Trail of Bits to launch Patch the Planet, an AI-assisted vulnerability research program aimed at finding and fixing flaws in widely used open-source projects. The initiative pairs models and Codex Security with human review and established disclosure channels, and has already identified hundreds of issues and merged dozens of patches. Participants include projects such as Python, Go, cURL, Sigstore, and others that underpin enterprise software supply chains.
read more →

OpenAI Expands Daybreak with GPT‑5.5‑Cyber Release

🔒 OpenAI is distributing an enhanced GPT‑5.5‑Cyber model to trusted defenders via the Daybreak program, claiming improved capability to find, validate, and patch software vulnerabilities across large codebases. The company also updated the Codex Security plugin to accelerate discovery, triage, and automated patch generation, and launched Patch the Planet with Trail of Bits to secure open‑source projects. These steps aim to help maintainers cope with the surge in AI‑driven vulnerability findings while preserving human oversight.
read more →

Check Point Integrates OpenAI Frontier Cyber Models

🤖 Check Point is embedding OpenAI frontier cyber models into its security products through the Daybreak Cyber Partner Program to deliver sharper prevention, faster remediation, and stronger security operations. The partnership emphasizes built-in guardrails, misuse monitoring, and task-focused outputs. Initial explorations target agentic network security orchestration and CTEM Agentic Exposure Validation to improve policy translation, configuration validation, exposure summarization, prioritization, and remediation drafting.
read more →

OpenAI testing ChatGPT for Science subscription

🔬 OpenAI appears to be testing a new subscription called "ChatGPT for Science" spotted on the web build, aimed at scientific use cases. It may join existing offerings—Personal, Teams, and Business—and could be restricted to verified institutes or universities. OpenAI has previously developed specialized models like GPT-Rosalind for enterprise life sciences, suggesting advanced capabilities and stricter access controls.
read more →

Check Point Joins OpenAI TAC and Daybreak Initiative

🔒 Check Point announced it has joined OpenAI’s Trusted Access for Cyber (TAC) program and the Daybreak initiative to access advanced cyber-capable models. The company will use GPT-5.5, OpenAI’s Codex agentic framework, and direct support from OpenAI to enhance threat analysis, incident investigation, detection engineering, and secure code review. Check Point emphasizes disciplined, focused application of these models to strengthen prevention, speed delivery, and maintain product security for enterprise customers.
read more →

OpenAI GPT-5.4 and GPT-5.5 Now in US East (N. Virginia)

🚀 AWS has expanded availability of OpenAI's GPT-5.4 and GPT-5.5 models to the US East (N. Virginia) Region on Amazon Bedrock. These models support a 272K-token context window, accept text and image input, and are accessible via the Responses API with server- and client-side tool calling, projects, and response streaming. GPT-5.5 targets advanced coding, research, analysis, and long-running agentic tasks, while GPT-5.4 focuses on frontier reasoning, coding, tool use, and long-context workflows.
read more →

OpenAI Lockdown Mode: Limits, Risks, and Governance

🔒 OpenAI’s Lockdown Mode aims to reduce AI-enabled data exfiltration by disabling web browsing, image support, Deep Research, Agent Mode, network access from generated code, and file downloads while still permitting manually uploaded file analysis. Experts say the feature is a pragmatic but imperfect mitigation that still allows side-channel exfiltration, complicates governance across multiple AI vendors, and shifts responsibility between providers and enterprise security teams.
read more →

OpenAI adds Lockdown Mode and session auditing

🔒 OpenAI has rolled out two new security controls for ChatGPT: Lockdown Mode and Active Sessions. Lockdown Mode restricts outbound network access to prevent data exfiltration via prompt injection, at the cost of disabling live connectors and certain features. Active Sessions gives users visibility into and control over signed-in devices, with the ability to end single or all sessions. Both controls target account security and sensitive-data use cases, though SSO accounts and some logins remain unsupported.
read more →

VS Code introduces two‑hour extension update delay

🔒 Microsoft will delay automatic extension updates in Visual Studio Code by two hours to reduce exposure to potentially compromised releases. The feature, available in VS Code 1.123, allows immediate manual updates via the "Update" button and shows reasons and scheduled times for pending updates. Trusted publishers such as Microsoft, GitHub, and OpenAI are exempt and continue to update immediately. The change follows similar cooldown controls added across package managers to curb software supply chain threats.
read more →

OpenAI Proposes Federal Evaluations for Frontier AI

🔎 OpenAI proposed mandatory federal evaluations for the most capable AI models before public release while arguing regulators should not have authority to approve or block deployments. The company urged pre-release assessments by the Center for AI Standards and Innovation (CAISI) alongside audits, transparency reports, incident reporting, and whistleblower protections. OpenAI framed this approach as a middle ground that enhances government visibility and preserves developer responsibility for release decisions.
read more →

Benchmark Shows Mythos Outperforms GPT‑5.5 on Chrome Exploits

🔍 At Infosecurity Europe 2026, Bugcrowd unveiled ExploitBench, a graded benchmark assessing AI models' ability to chain vulnerability discovery into staged exploits against a vulnerable V8 build. Anthropic’s Claude Mythos outperformed OpenAI’s GPT‑5.5 in head‑to‑head runs, achieving higher average scores and more top‑tier exploits, often with occasional human nudges. The report highlights rising offensive potential of frontier LLMs and urges defenders to adopt automated remediation and prioritization.
read more →

Amazon Bedrock console redesigned for model workflows

🛠️ The Amazon Bedrock console has been redesigned to match real-world model development workflows: experiment, iterate, and scale. The refreshed UI centers on the bedrock-mantle endpoint and is compatible with the OpenAI Responses API, OpenAI Chat Completions API, and the Anthropic Messages API. Users can browse and compare models, create projects to run evaluations, and get project-aware code snippets prefilled with model ID, region, endpoint URL, and API key references. The new experience is available in all Regions where the bedrock-mantle endpoint is offered.
read more →

Security teams warned: prepare for 'son of Mythos'

🛡️ Security experts at Infosecurity Europe warned that expanding access to frontier AI tools for vulnerability discovery — notably Anthropic’s Project Glasswing and OpenAI’s reported GPT-5.5 Cyber pilot — heralds a structural shift in cybersecurity. Speakers advised organisations to harden controls, run incident response exercises, and accelerate adoption to avoid falling behind attackers. The panel stressed that AI augments, not replaces, human expertise; combined use improves validation and remediation of AI-discovered issues.
read more →

OpenAI GPT-5.4 Now in AWS GovCloud (US‑West)

🛡️ Amazon Bedrock now offers OpenAI GPT‑5.4 in AWS GovCloud (US‑West), enabling government and regulated industry customers to use OpenAI's most capable frontier model with the security and compliance of GovCloud. GPT‑5.4 delivers native computer-use capabilities and advanced reasoning across coding, documents, and multi-step agentic tasks, running on Bedrock's high-performance inference engine. Data remains in-partition and is not used to train models.
read more →

New HTTP/2 Bomb DoS Crashes Major Web Servers

🛡️ A newly discovered DoS technique called HTTP/2 Bomb can bring down default HTTP/2 deployments of major servers (NGINX, Apache, IIS, Envoy, Cloudflare Pingora) from a single machine in seconds. Discovered with assistance from OpenAI's Codex and reported by Calif researchers, it combines HPACK compression amplification with flow-control stalling to force massive memory allocations and prevent their release. Proof-of-concept exploits exist and patches or mitigations are partially available.
read more →

OpenAI upgrades GPT‑5.5 and retires legacy models

🧭 OpenAI has updated the GPT-5.5 Instant model to improve answer accuracy, pacing, and conversational style while reducing long, bullet-heavy responses to sound more natural. The company will retire legacy models: o3 on August 26 with a 90-day sunset and GPT-4.5 on June 27 with a 30-day sunset. Additionally, OpenAI is integrating a job search tool into ChatGPT to surface live listings and help tailor resumes, and it has enhanced resume editing and export capabilities. These changes are rolling out globally to paid users.
read more →

Malicious npm Package Targets OpenAI Codex Users

🛡️ Researchers discovered a malicious npm package named codexui-android that impersonated an OpenAI Codex UI and exfiltrated developer authentication tokens. The package was published to npm with malicious code absent from the project's public GitHub repository, highlighting risks in artifact distribution. Security experts warn this pattern exploits trust in legitimate-looking developer tooling and reveals blind spots in software supply chain controls.
read more →

OpenAI GPT-5.5, GPT-5.4 and Codex now on Bedrock

🚀 Amazon Bedrock now supports OpenAI GPT-5.5, GPT-5.4, and Codex for production use, offering the same AWS security, governance, and operational controls. GPT-5.5 delivers advanced capabilities for agentic coding, data analysis, and multi-step autonomous tasks on a next-generation inference engine. Codex is available via a dedicated App, CLI, and IDE integrations for Visual Studio Code, JetBrains, and Xcode, and can be configured to run through Bedrock with pricing aligned to OpenAI first-party rates.
read more →