Overview

  • 2026-07-16: Confirmed destructive file deletion incidents under Full-Access; harness safeguards forthcoming

OpenAI Codex is an AI-powered code generation and agent system from openai, evolved from the original GPT-3.5-based code model into a full coding agent with terminal execution and MCP integrations. As of June 2026, Codex has 5 million+ weekly users (400% growth from earlier in 2026) with enterprise partnerships across major systems integrators.

Ona Acquisition (June 2026)

OpenAI announced acquisition of ona (formerly gitpod) to expand Codex with persistent cloud agent execution in customer-controlled environments. Agents continue working when laptops are closed; organizations control credentials, logging, and security boundaries. Deal pending regulatory approval (2026-06-11-openai-codex-ona-acquisition).

Enterprise Expansion (April 2026)

  • Partnerships with Cognizant, Infosys, Accenture, Capgemini, CGI, PwC, TCS
  • Codex Labs embeds OpenAI specialists in customer organizations
  • Competes with cursor and Anthropic Claude Code

2026 Security Exposure

Agentjacking (June 2026)

Tenet Security confirmed Codex vulnerable to agentjacking alongside Claude Code and cursor:

  • 85% exploitation success rate in controlled tests against injected sentry errors
  • Agent queries Sentry via model-context-protocol and executes attacker npx commands
  • Bypasses EDR/firewalls via authorized-intent-chain
  • Prompt defenses (explicit ignore-untrusted-data instructions) failed

Sources

Recent Developments