OpenAI Codex Security Scans 1.2M Commits, Flags 10,561 Bugs

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI began rolling out Codex Security on Friday as an AI-powered security agent that finds, validates, and proposes fixes for vulnerabilities, available in research preview to ChatGPT Pro, Enterprise, Business, and Edu customers with free usage for the next month.
- Codex Security scanned more than 1.2 million commits across external repositories over the last 30 days of its beta, identifying 792 critical findings and 10,561 high-severity findings in projects including OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP, and Chromium.
- Codex Security represents an evolution of Aardvark, the security agent OpenAI unveiled in private beta in October 2025, now leveraging frontier model reasoning combined with automated validation to reduce false positives.
- OpenAI reported that false positive rates fell by more than 50% across all repositories during repeated scans, attributing the improvement to grounding vulnerability discovery in system context and validating findings before surfacing them.
- Codex Security works in three stages: building an editable threat model of a project's structure, identifying and classifying vulnerabilities by real-world impact, and pressure-testing flagged issues in a sandboxed environment before proposing fixes.
- Anthropic launched a competing product, Claude Code Security, weeks earlier to help users scan codebases for vulnerabilities and suggest patches.
Why it matters: Codex Security is rolling out to enterprise and business tiers for free for a month, giving security teams direct access to an AI agent that already generated tens of thousands of findings during beta. With Anthropic shipping a similar Claude Code Security product weeks earlier, AI-driven vulnerability scanning is now a two-horse race between the largest AI labs, and the 50%+ drop in false positives addresses the single biggest complaint about automated security tools.
Ask SkimNews



