Weekly review

ThreatNoir Morning Brief — March 31

2026-03-31Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — March 31, 2026

The cybersecurity landscape continues to face mounting pressure as artificial intelligence platforms and critical infrastructure components reveal dangerous vulnerabilities. Today's briefing covers multiple active threats affecting both enterprise systems and widely-used development tools, with attackers actively exploiting several disclosed flaws.

OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens

A critical vulnerability in OpenAI Codex has been discovered that enabled attackers to steal GitHub tokens through a sophisticated attack vector involving malicious branch names. The flaw leveraged a hidden Unicode command injection technique to compromise authentication credentials without user awareness. Source: OpenAI Codex Vulnerability Allowed Attackers to Steal GitHub Tokens

This vulnerability represents a significant supply chain risk, as compromised GitHub tokens could grant attackers unauthorized access to repositories and sensitive code. The attack method demonstrates how seemingly innocuous inputs can be weaponized through Unicode obfuscation to execute shell commands within the Codex environment. Organizations relying on Codex for development workflows should review their token management practices and implement additional access controls.

Critical Citrix NetScaler Memory Flaw Actively Exploited in Attacks

Threat actors are actively exploiting a critical memory vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances tracked as CVE-2026-3055. The flaw enables attackers to extract sensitive data from affected systems, and exploitation attempts have been documented in the wild. Source: Critical Citrix NetScaler memory flaw actively exploited in attacks

A related vulnerability, CVE-2026-4368, has also been identified in the same product line, expanding the scope of potential compromise. Organizations operating Citrix NetScaler infrastructure should prioritize patching these vulnerabilities immediately, as active exploitation indicates attackers are actively targeting these systems in production environments. Network monitoring and access logs should be reviewed for indicators of compromise.

F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation

CVE-2025-53521 has been reclassified from a high-severity denial-of-service flaw to a critical remote code execution vulnerability following new technical analysis. Originally disclosed in October, the vulnerability's true nature has only recently been understood, and active exploitation attempts have already begun. Source: F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation

This reclassification underscores the importance of continuous vulnerability assessment and the risk that initial severity ratings may underestimate actual threat potential. Organizations operating F5 BIG-IP systems should treat this vulnerability with the highest priority and deploy patches without delay, particularly given the evidence of active exploitation in the threat landscape.

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

OpenAI has released patches addressing a previously unknown vulnerability in ChatGPT that permitted sensitive conversation data to be exfiltrated without user knowledge or consent. Research from Check Point revealed that a single malicious prompt could transform an ordinary conversation into a covert data exfiltration channel, leaking user messages, uploaded files, and other sensitive information. Source: OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

The vulnerability represents a fundamental security concern for AI platforms, as it demonstrates how prompt-based attacks can bypass normal security boundaries. Users of ChatGPT and other OpenAI services should ensure they are running the latest patched versions. This incident, combined with the Codex token theft vulnerability, illustrates a broader pattern of security challenges emerging in AI-powered development and communication tools that warrant heightened vigilance from security teams.


Today's threat landscape demonstrates that vulnerabilities affecting both specialized infrastructure components and mainstream AI platforms demand immediate attention from security teams. Patching critical systems, reviewing access controls, and monitoring for active exploitation should be prioritized across all affected environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
MITRE ATT&CK4