What happened
At DevDay (Sept 29), OpenAI launched Codex Security Cloud: developers can scan entire GitHub repositories on demand or on a schedule (including on every new commit), with Codex investigating findings, de-duplicating, and preparing fixes in the cloud even while the laptop is closed. It now includes access to Daybreak Blue cyber-capable models by default, with no separate application process.
Why it matters
It productizes agentic, always-on code security directly inside the leading coding-agent ecosystem, bundling frontier cyber-reasoning models into routine appsec workflows — a meaningful step function in AI-for-cybersecurity availability to mass developer audiences rather than just SOC teams.
Applicability
Development and AppSec teams standardized on Codex/GitHub should pilot immediately for continuous repo scanning and auto-fix; security teams should assess prompt/fix-review workflows given autonomous remediation.