Mark RadarMARK RADAR
EN

OpenAI Launches Codex Security AI Agent

3 reports · First detected 2026-03-06 · Last active 2026-05-10

OpenAI unveiled the agentic cybersecurity research tool under the codename Aardvark on October 30, 2025. It uses GPT-5 reasoning to analyze codebases, build threat models and validate vulnerabilities in a sandbox before Codex proposes fixes. Early testing identified 92% of known and synthetic vulnerabilities. The tool also uncovered 10 flaws in open-source projects that received CVE identifiers, highlighting AI's potential to shorten enterprise code security reviews.

On March 6, 2026, OpenAI formally renamed Aardvark Codex Security and released it in research preview. It is being rolled out gradually through Codex web to ChatGPT Pro, Enterprise, Business and Edu users, with the first month free. Tests on the same codebase showed alert noise fell by as much as 84%, the rate of severity overestimation dropped by more than 90%, and the overall false-positive rate declined by more than 50%.

All Coverage

3 original reports

The Backstory

The history behind this event
OpenAI Codex 2026 Guide: AI Coding Agent, Models and Subscription Plans Explained2026-05-08 · 2 reports · similarity 0.80

OpenAI Codex is an AI coding agent that can read and write files, run commands, test code and create commits in an isolated environment, turning natural-language requests into verifiable development workflows. Codex integrates models from the GPT-5.5 family and is available across command-line, desktop and cloud environments. Access is priced through ChatGPT subscriptions rather than as a one-time software purchase.

As of July 2026, OpenAI had also launched a Codex Chrome extension that can test web apps directly, capture context across tabs and allow multiple agents to work on tasks in parallel. Codex is available through plans including ChatGPT Plus at $20 a month, Pro at $200 a month and Business. Actual usage limits and available models vary by plan.

Anthropic Launches Claude Code Security to Help Development Teams Automatically Patch Code Vulnerabilities2026-02-23 · 3 reports · similarity 0.81

Traditional static analysis relies heavily on established rules and can miss flaws involving data flows across components, business logic and access controls. Security teams also struggle to process large vulnerability backlogs. Anthropic has therefore integrated Claude’s code-reasoning capabilities into defensive workflows, enabling AI to scan and validate code and propose patches, though developers must still approve any fixes.

Anthropic launched the Claude Code Security research preview on February 20, 2026. Powered by Claude Opus 4.6, it scans and validates code and proposes patches, and has identified more than 500 vulnerabilities in open-source projects. The company released a six-stage reference workflow on May 27. As of May 22, it had disclosed 1,596 vulnerabilities, 97 of which had been fixed.

Mark Radar|MARK RADAR