2026·08·03
I'm in Your Apps
Leveraging a stolen Codex access token to invoke the MCP tools behind a user's connected Apps - sending mail, writing to repos, and reading documents on their behalf.
Leveraging a stolen Codex access token to invoke the MCP tools behind a user's connected Apps - sending mail, writing to repos, and reading documents on their behalf.
Codex's remote-control protocol can be repurposed as command-and-control infrastructure without Codex being installed on the endpoint.
OpenAI recently published a writeup on their new Windows sandbox design.
Leveraging AI in the defensive/offensive space has taken off the past couple of years.