OpenAI said it will acquire Ona, formerly Gitpod, as part of a push to give Codex persistent, secure cloud development environments instead of relying on a developer’s local machine. The move is intended to let coding agents keep working across longer-running tasks in customer-controlled workspaces, extending Codex beyond short interactive sessions and supporting more autonomous software development workflows.
Reporting on OpenAI’s product roadmap said the company expects Codex to evolve quickly enough that today’s version will soon appear "primitive," with expansion planned across desktop, mobile, and parallel task management. The shift to cloud-hosted agent workspaces is positioned as a foundation for that roadmap, but it also raises security concerns for enterprises, including access control, isolation, and governance over AI agents operating continuously inside development environments.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
In early July, OpenAI launched a new GPT-5 model for Codex. The New Stack reports Codex surpassed 8 million users shortly after the GPT-5 launch.
In June, OpenAI said it plans to acquire Ona, formerly Gitpod, as part of the next phase of Codex. OpenAI said Ona's secure cloud development environments would help agents keep working in a customer's cloud after the initiating laptop is closed.
In February, OpenAI published an experiment in which Codex worked continuously for about 25 hours, using around 13 million tokens and generating roughly 30,000 lines of code to build a design tool from scratch.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.