Fetching from the wire…
Public story · 2026-03-16 · source-backed
OpenAI went public with Codex Security's numbers, and they're significant enough to pay attention to.
The AI security agent — evolved from the Aardvark private beta — has scanned over 1.2 million commits in the past 30 days, surfacing 792 critical and 10,561 high-severity findings across major open-source projects including OpenSSH, GnuTLS, Chromium, and PHP. False positive rates have dropped more than 50% across successive scans as the agent builds project-specific context. Available free for one month to ChatGPT Pro, Enterprise, Business, and Edu customers. The Hacker News
What makes this more than a marketing number: OpenAI simultaneously published a technical blog explaining why Codex Security doesn't include a traditional SAST report. Their argument is that rule-based scanning cannot model logic flaws, novel injection patterns, or misconfigured cryptography — the agent uses constraint reasoning that detects vulnerabilities requiring multi-file context. OpenAI Blog
The convergence matters. Both OpenAI and Anthropic exposed SAST's structural blind spot in the same week — the first time two frontier labs have published converging security methodology conclusions simultaneously. Meanwhile, Binarly open-sourced VulHunt with native MCP server mode and Claude Skills instruction files, making binary vulnerability scanning composable in agentic security pipelines. Help Net Security The AI security agent category is forming fast, and the tools that AI agents can invoke for security analysis are proliferating faster than the attack surfaces they're meant to defend.
Each link below shares sources, entities, or timing with this story.
Codex Security benchmarked against OpenSSH / Shared entities / Same source / Shared topic / Earlier coverage
Linked by a graph relationship (Codex Security benchmarked against OpenSSH); both cover Business, Chromium, Codex Security, Enterprise; cite the same source (The Hacker News).
OpenAI supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover Aardvark, Anthropic, Chromium, Codex Security; reported by the same outlet (openai.com).
OpenAI supports MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover Codex Security, Enterprise, High, OpenAI; reported by the same outlet (openai.com).
Microsoft supports MCP / Shared entities / Shared topic / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover Anthropic, Business, Enterprise, Meanwhile; overlapping topics (have, security).
OpenAI supports MCP / Shared entities / Same source / Shared topic / What happened next
Linked by a graph relationship (OpenAI supports MCP); both cover Codex Security, OpenAI; cite the same source (The Hacker News).
Microsoft supports MCP / Shared entities / Same source domain / What happened next / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover Anthropic, MCP, OpenAI, The Hacker News; reported by the same outlet (thehackernews.com).
Cursor uses MCP / Shared entities / Same source domain / What happened next / Tension
Linked by a graph relationship (Cursor uses MCP); both cover Anthropic, Business, Meanwhile, OpenAI; reported by the same outlet (openai.com).
Microsoft supports MCP / Shared entities / What happened next
Linked by a graph relationship (Microsoft supports MCP); both cover Anthropic, Business, Enterprise, MCP; picks up the Anthropic thread on 2026-07-30.