Today: May 30, 2026

Fletcher Davis

Fletcher Davis, Director of Research for BeyondTrust Phantom Labs

AI coding agent flaw exposed: GitHub tokens at risk

Researchers at BeyondTrust Phantom Labs have identified a critical command injection vulnerability in OpenAI’s Codex cloud environment that exposed GitHub OAuth tokens directly from the agent’s execution environment. The vulnerability stemmed from
2 months ago

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy