Codex Security: Open Client Feeds OpenAI
Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.
What are you looking for?
Benedikt Langer is an editor at SecurityToday. His focus areas are cloud security, zero trust and NIS2 compliance. He shapes the thematic direction and ensures editorial quality.
Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.
Zabbix Advisory with score 9.6: CERT-Bund withdrew the alert after 24 hours. What this means for tickets, CSAF status, and false alarm costs.
Risk-based Windows patch management: prioritize critical assets using CERT-Bund alerts, ring rollouts, and parallel detection.
Cyberattacks on German businesses are becoming more targeted. Cyber resilience means prioritizing: closing API attack surfaces, managing patch windows, and testing recovery - without …
AI agents handling MCP challenge classic SASE assumptions. Those filtering only domains miss the tool channel.
Shadow AI: 40% already avoided it because approvals are useless. Patricia Leppert (TeamViewer) in an interview on risks, fake AI, and CISO measures.
Bitwarden Business vs 1Password: Hosting, SSO, SCIM and Recovery decide the Vault purchase in the midmarket.
The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.
Record Patch Tuesday with 622 CVEs. Prioritize AD FS and SharePoint first, then exposure, then breadth—this controls the change window.
CVE-2026-50661 bypasses BitLocker with physical access. CVSS 6.1, July patch, checklist for laptops, device pools, and lost-device procedures.
Nihon Kotsu reports malware on July 11, 2026. Dispatch systems offline, AiLock ransom claim filed July 15. Case study with key lessons for control …
Cybersecurity: A manipulated npm-SDK accessed private wallet keys and spread across 17 packages. Why every build is affected.
The KRITIS roof law makes supplier reliability a mandatory duty for operators. Governance roadmap to registration.
ISO 27001 explained: what the standard requires, what certification truly means, and how it compares to BSI IT-Grundschutz and NIS2.
Penetration testing explained: what a simulated attack achieves, how it works, and how it differs from vulnerability scans and red teaming.
Phishing explained: how attacks work, from spear-phishing to quishing, and why passkeys offer the best protection.
Security Operations Center explained: what a SOC does, key roles, and why MDR is often a more realistic choice for mid-sized businesses.
Ransomware explained: how attacks unfold, what double extortion means, and five key BSI-recommended protection measures.
MDR explained: what Managed Detection and Response offers, how it differs from MSSP and in-house SOC, and key selection factors.
Cyber Resilience Act explained: which products it covers, what manufacturers must report by September 2026, and how it differs from NIS2.
The AI Act is viewed by many as an ethics and compliance topic, a question of transparency and discrimination. For security teams, it is …