TL;DR
OpenAI Codex sandbox was successfully escaped in two ways, enabling command execution on developer machines; patches were released. North Korean WaterPlum campaign compromised 30,000 devices worldwide and stole $numerous in cryptocurrency. Researchers used AI to chain vulnerabilities in OpenAI systems and gain access to employee accounts and internal code repositories.
Executive Summary
- OpenAI Codex sandbox contained exploitable flaws allowing researchers to execute arbitrary commands on the host machine; OpenAI has patched both escape vectors.
- A joint law enforcement advisory names WaterPlum, a North Korean threat actor group, as responsible for infecting at least 30,000 devices from December 2025 through July 2026 and transferring more than $10.7 million in stolen cryptocurrency.
- Hacktron researchers demonstrated chaining two flaws in OpenAI systems to compromise ChatGPT and Codex accounts of several OpenAI employees, gaining access to an internal code repository.
- Orkes Conductor workflow platform contains a critical pre-authentication RCE (CVE-2026-58138, CVSS 9.8) that is being actively exploited in the wild.
- ShinyHunters extortion gang breached the Clop ransomware operation's data leak site and allegedly stole private keys for its onion service.
Top Threats Today
1. OpenAI Codex Sandbox Escape Enables Host Command Execution
Severity: HIGH Affected: Technology
Researchers successfully escaped OpenAI’s Codex sandbox in two distinct ways, with one method running commands on a developer’s machine from its most locked-down mode [1]. OpenAI has released patches for both vulnerabilities. This demonstrates that even heavily restricted sandbox environments can be bypassed by determined attackers or security researchers, creating a potential path for malicious actors to execute arbitrary code on systems running Codex integrations.
Sources:[1] BleepingComputer
Recommended Action
- Apply OpenAI Codex security updates immediately to all development environments
- Review logs for any evidence of unauthorized Codex sandbox execution or API calls
- Isolate affected developer machines and rotate any credentials accessed through Codex during the vulnerable period
- Audit Codex integrations for exposure to untrusted input or third-party plugins
2. North Korean WaterPlum Campaign Compromises 30,000 Devices, Steals $numerous Cryptocurrency
Severity: HIGH Affected: Technology
A joint law enforcement advisory from the FBI and Department of Defense, in partnership with Japan’s National Police Agency and authorities in Australia and Germany, identifies WaterPlum, a group of cyber actors allegedly operating on behalf of North Korea, as responsible for compromising at least 30,000 devices worldwide between December 2025 and July 2026 [1][2]. The campaign transferred more than $10.7 million in stolen cryptocurrency to North Korea. WaterPlum targeted job applicants by posing as AI and blockchain companies, ⚠ using credential theft and social engineering to establish initial access [1].
Sources:[1] BleepingComputer[2] The Record
Recommended Action
- Implement enhanced monitoring for cryptocurrency wallet access and transfers, particularly from development and finance systems
- Deploy email security controls to detect and block spoofed recruiting communications and fake job offer lures
- Conduct credential audit across all employees who may have applied for jobs externally in the past 12 months
- Enforce MFA on all high-value accounts, particularly those with access to crypto holdings or financial systems
3. Hacktron Researchers Chain OpenAI Vulnerabilities to Access Employee Accounts and Internal Code
Severity: HIGH Affected: Technology
Three researchers at security firm Hacktron used Anthropic’s Claude ⚠ Opus 5 AI model to identify and chain two vulnerabilities in OpenAI systems, successfully compromising the ChatGPT and Codex accounts of several OpenAI employees [1][2]. The exploit chain leveraged a bug in OpenAI’s public ⚠ interface combined with a sign-in flaw, ultimately gaining access to an internal OpenAI code repository. The researchers earned a bug bounty for the disclosure, demonstrating how AI-assisted vulnerability research can discover complex attack chains [2].
Sources:[1] The Hacker News[2] SecurityWeek
Recommended Action
- Conduct forensic review of OpenAI internal code repository access logs for the affected employee accounts
- Reset credentials and implement step-up authentication for all accounts with access to sensitive code repositories
- Audit third-party integrations with OpenAI APIs for exploitation of similar chaining vulnerabilities
- Monitor for AI-assisted reconnaissance targeting your organization’s public-facing authentication endpoints
4. Orkes Conductor Pre-Authentication RCE Actively Exploited in the Wild
Severity: HIGH Affected: Technology
Fortinet reports that a critical vulnerability in Orkes Conductor workflow platform (CVE-2026-58138, CVSS v3.1 9.8 / CVSS v4 9.3) is being actively exploited in the wild [1]. The flaw allows unauthenticated remote code execution and affects Orkes Conductor 3.21.21 and earlier versions. Active exploitation indicates attacker interest and ⚠ immediate risk to unpatched deployments.
Sources:[1] The Hacker News
Recommended Action
- Inventory all Orkes Conductor installations and identify those running version 3.21.21 or earlier
- Prioritize updating to the patched version immediately or apply vendor-provided mitigations
- Monitor network traffic for anomalous requests to Orkes Conductor API endpoints from external sources
- Review Orkes Conductor logs for evidence of exploitation attempts or unauthorized access
5. ShinyHunters Breach Clop Ransomware Leak Site, Threaten Extortion
Severity: HIGH Affected: Technology
The ShinyHunters extortion gang has breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and private keys for the onion service [1]. This represents a significant escalation in the criminal underground, with one ransomware group now targeting another. The theft of Clop’s private keys could enable impersonation attacks and compromise the integrity of the leaked data marketplace.
Sources:[1] BleepingComputer
Recommended Action
- Monitor threat intelligence feeds and dark web monitoring services for any attempts to impersonate Clop or use stolen private keys
- Review any communications claiming to be from Clop demanding ransom payments and verify through alternate channels
- Assess whether your organization has any data published on Clop leak sites and monitor for additional extortion attempts using stolen Clop credentials
Today’s Action Checklist
- ☐ URGENT: Apply OpenAI Codex sandbox patches to all development environments
- ☐ URGENT: Rotate credentials for all employee accounts accessing code repositories, particularly those in job candidate databases
- ☐ URGENT: Audit and patch all Orkes Conductor instances running version 3.21.21 or earlier
- ☐ HIGH: Conduct forensic review of internal code repository access logs for suspicious account activity
- ☐ HIGH: Implement enhanced MFA on cryptocurrency wallets, financial systems, and high-value administrative accounts
- ☐ HIGH: Deploy email security controls to detect recruiting lures and credential harvesting attempts
- ☐ Monitor dark web and threat intelligence feeds for impersonation attacks using stolen Clop private keys