← Back to feed
AI SecurityEmerging1 sourceAug 2, 2025 · 07:31via Embrace The Red (AI agent security)

Turning ChatGPT Codex Into A ZombAI Agent

Brief

Today we cover ChatGPT Codex as part of the Month of AI Bugs series.

ChatGPT Codex is a cloud-based software engineering agent that answers codebase questions, executes code, and drafts pull requests.

In particular, this post will demonstrate how Codex is vulnerable to prompt injection, and how the use of the “Common Dependencies Allowlist” for Internet access enables an attacker to recruit ChatGPT Codex into a malware botnet.

Read more on Embrace The Red (AI agent security)