this is pretty cool also – they are relaxing the safety related internet security restrictions, so in an attempt to teach you, they just teach you how to prompt inject Codex (cc @simonw
) https://
developers.openai.com/codex/cloud/in
ternet-access
… you can pretty easily use this to leak api keys, customer data
SECURITY
-

OpenAI Codex Internet Access Creates Prompt Injection Security Risks
By
–
-

AI Reply Bots Pose Existential Risk to X Platform
By
–
I still think the biggest existence risk for X is AI reply bots They're rampant and my understanding of AI is you can only detect an AI reply with a model that's bigger/smarter than the model it's written with That means you're in an endless cat and mouse game for the infinite
-

Own Your GPU: Securing AI Compute Independence From Corporations
By
–
friendly reminder to buy a GPU and secure your compute on this wonderful day in LLMs not your weights means eventually not the same model – they have all the knobs and you're at their mercy your AI cannot be controlled by a self-serving corporate
-

OpenAI ChatGPT Monitoring Law Enforcement Privacy Implications
By
–
Big alert: OpenAI now scans ChatGPT chats & passes flagged content to law enforcement. The intention is to stop harmful or illegal use, but when private convos might be reviewed, how private is private anymore? Questions:
1Where should firms draw the line on monitoring? -
Addressing AI-Related Tragedies: Urgent Action Required
By
–
We must do whatever it takes to stop the killers behind these tragedies
-
Public-Private Partnerships Strengthen Secure AI Development Standards
By
–
Our collaboration with the US Center for AI Standards and Innovation (CAISI) and UK AI Security Institute (AISI) shows the importance of public-private partnerships in developing secure AI models.
-
AI Security: Mitigating Prompt Injection and System Vulnerabilities
By
–
If there's no known fix for those then they are indeed similar to prompt injection What's the recommended mitigation for people with security concerns that are serious enough for this to be a concern? Air-gapped machines? Back to pen and paper messages sent using one-time pads?
-
Cybersecurity alert: AI voice cloning and deepfakes
By
–
2. Cybersecurity PSA (AI voice cloning alert)
— God of Prompt (@godofprompt) 12 septembre 2025
Prompt:
Create a post about a cybersecurity alert for IT administrators about new social engineering tactics powered by AI voice cloning and deepfakes.
What SynthMind did: Produced a professional LinkedIn/X-style post with a… pic.twitter.com/3O2tM2Uh5M— 2. Cybersecurity PSA (AI voice cloning alert) Prompt: Create a post about a cybersecurity alert for IT administrators about new social engineering tactics powered by AI voice cloning and deepfakes. What SynthMind did: Produced a professional LinkedIn/X-style post with a —
-
GitHub Domain Allow-listing Security Risk Analysis
By
–
I don't think there are any endpoints on http://
GitHub.com itself that could expose logs of incoming GET requests to anyone outside of GitHub/microsoft employees It does make me nervous that all of that domain is allow-listed though, feels like the riskiest entry in there -
FFmpeg sandbox integration security vulnerability analysis
By
–
I don't see why it would add any new vulnerabilities, the main safety feature of the sandbox is that it can't make network calls and ffmpeg wouldn't change that