Untangling a Linux Incident With an OpenAI Twist (Part 2)
Reported 22 Apr 2026 by otx · Severity: medium
A Linux endpoint was simultaneously compromised by at least two distinct threat actors while the developer user relied on OpenAI's Codex AI agent for security remediation. Actor A deployed a cryptominer mining Monero to a private pool. Actor B installed a multi-revenue botnet inc