OpenAI announced plans to acquire Promptfoo, positioning the deal as a way to strengthen security testing for AI agents and application workflows, alongside separate claims that its Codex Security capability identified 11,000 “high-impact” bugs in a month. The coverage frames these moves as part of a broader push toward automated, AI-assisted security validation in software development and DevSecOps, with an emphasis on scaling vulnerability discovery and testing as organizations adopt agentic AI.
Other items in the set are largely opinion/feature pieces or unrelated security-policy reporting rather than additional reporting on the OpenAI/Promptfoo transaction or Codex Security results. Notably, one article reports that CVE program funding was secured, easing concerns about continuity of the vulnerability identifier ecosystem, while several other references discuss general themes such as IAM strategy in the public sector, access-decision risk in identity security, OT/legacy industrial cyber risk, SOC preparation for agentic AI, and post-quantum cryptography (PQC) planning—useful context, but not the same specific event as the OpenAI acquisition or Codex Security claim.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CSO Online reported that OpenAI planned to acquire Promptfoo to strengthen security testing for AI agents. The reference does not include transaction terms or a more specific announcement date beyond publication timing.
A CSO Online item reported that OpenAI said its Codex Security tool identified 11,000 high-impact bugs over the course of one month. The reference provides only headline-level detail and does not specify the month or affected organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.