Tag

security

/ 2 posts
2026·08·03

I'm in Your Apps

Leveraging a stolen Codex access token to invoke the MCP tools behind a user's connected Apps - sending mail, writing to repos, and reading documents on their behalf.

2026·07·27

WHAM, Bam, Thank You OpenAI for the C2 Infrastructure

Codex's remote-control protocol can be repurposed as command-and-control infrastructure without Codex being installed on the endpoint.