Open Source · OpenAI · Codex · GPT · Mythos · Calif · Wired
OpenAI Releases Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.
✓ KHAO Verified
As fears about AI hacking capabilities grow, OpenAI on Monday made a slew of cybersecurity-focused announcements, including an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and other institutions to give them “trusted access” to the company's latest cybersecurity-focused models, and releasing its Codex Security scanner as an app plug-in.
Key facts
- Matin adds that for its Codex Security scanner, which has been in research preview since earlier this year, OpenAI has been subsidizing usage for both open-source and private code “to the tune of 20 trillion tokens
- More than 30 open-source projects are already participating in Patch the Planet, with more in the pipeline to start
- Patch the Planet is an internet-scale effort to help open-source software get ahead of AI bug-hunting tools,” says Trail of Bits CEO and cofounder Dan Guido
- Maintainers “do their work out of love of open source, and now they’re stuck reviewing slop CVEs,” says OpenAI's cyber tech lead, Fouad Matin
Summary
As advances across the AI industry leave critical open-source projects at increasing risk of falling behind, though, the company also said on Monday that it is launching an effort known as Patch the Planet, founded with the prominent research-focused security firm Trail of Bits and in collaboration with vulnerability management firms HackerOne and Calif. The project has already begun its work offering free security consulting services to open source maintainers to not only help them find and patch vulnerabilities, but also support them in strengthening their code bases and incorporating AI security tools into their development process.
Open-source developers—typically volunteers keeping critical and widely used software afloat with few resources—are often already struggling to keep up with bug reports.