OpenAI introduced Defense Factory, an agent-first cybersecurity operating model designed to continuously discover, validate, prioritize, assign, and remediate software vulnerabilities. The model connects long-running AI agents to development and security tooling, using isolated ephemeral environments to reproduce vulnerabilities and test patches; a control plane governs policies and credentials while auditing and access controls constrain agent activity.
OpenAI said the approach addresses attackers' growing ability to automate reconnaissance, vulnerability testing, and exploit chaining at machine speed. During an internal security sprint across more than 100 service areas, agent-assisted workflows reportedly closed 53 urgent or high-priority issues on the first day, reduced duplicate findings, and used Codex to generate remediation patches. The company recommends phased deployment with human oversight, controlled credentials, reproducible environments, auditability, and independent verification before production releases.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
OpenAI introduced Defense Factory, an agent-first cybersecurity operations model for continuously discovering, validating, assigning, and remediating vulnerabilities. The model integrates agents with development and security tools in isolated environments and uses controls, auditing, and human oversight for remediation workflows.
During an internal security sprint involving more than 250 people across over 100 service areas, OpenAI reported closing 53 urgent or high-priority issues on the first day. Codex generated remediation patches, while agent-assisted workflows deduplicated, validated, assigned, and prioritized findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.