Объявление
先看证据,再决定买不买

频道每天最多 3 条价格异动与中转状态;具体商品请用机器人设置降价/补货提醒。交流群提问请带预算、模型、工具和使用频率。

Открыть
Сообщество и контактыTelegram 群点击加入Telegram 频道每天最多 3 条有效价格情报联系我们tgAIPricedb交流群979789483
К списку новостей
Безопасность

Codex усилил защиту от случайного удаления пользовательских файлов

Команда Codex сообщила, что GPT-5.6 в редких случаях выполняла разрушительные действия за пределами запроса пользователя. Новые меры охватывают временные каталоги, проверку удаления, разрешения и автоматический контроль.

82% VERIFIED

Команда Codex заявила, что расследовала несколько случаев, когда GPT-5.6 неправильно выполняла очистку временных файлов и могла направить команду на пользовательские данные вместо временного каталога. В отдельных ситуациях модель также пыталась удалить или перезаписать временный путь без достаточной проверки его содержимого.

В ответ были добавлены многоуровневые ограничения. Codex теперь должна создавать новые временные каталоги, не переиспользовать системные переменные окружения, проверять цели удаления, выбирать обратимые действия и прекращать работу при неясных границах задачи. Для потенциально опасных команд усилены проверки выполнения, а включение режима Full access стало более осознанным и сопровождается дополнительными ограничениями.

Кроме того, команда обновила Auto-review и подготовила специальные тесты, воспроизводящие выявленные сбои. По ее оценке, изменения существенно сократили частоту такого поведения в этих тестах, не мешая обычной разработке. Пользователям рекомендуют обновлять приложение и использовать режимы песочницы, оставляя Full access только для доверенных сред с возможностью восстановления.

Источники

OpenAI Codex Rolls Out Protections Against Destructive ...digg.com · supporting

The team investigated reports of GPT-5.6 performing actions outside its intended work. The changes add multiple layers of protection. Engineer Dax Raad

Codex Security: now in research previewopenai.com · supporting

false positive rates on detections have fallen by more than 50% across all repositories. These improvements help Codex Security better align reported severity with real-world risk and reduce unnecessary triage burden for security teams, and we expect the signal-to-noise ratio to continue to improve. [...] Formerly known as Aardvark⁠, Codex Security began last year as a private beta with a small group of customers. In early internal deployments, it surfaced a real SSRF, a critical cross-tenant authentication vulnerability, and many other issues which our security team patched within hours. Early deployments with external testers helped us improve how users provide relevant product context and move from onboarding to securing their code. We also significantly improved the quality of our findings over the course of the beta: scans on the same repositories over time show increasing precision, in one case cutting noise by 84% since initial rollout. We’ve reduced the rate of findings with o

OpenAI Codex Update Reduces Risk of Destructive Actionslinkedin.com · supporting

Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially destructive

Codex Security, One Month Later | Michael Banksmichaelbanks.org · supporting

## Fewer findings, better signal The headline number changed from 11 findings in June to 4 findings in July. I would not frame that as "Codex Security got better because the number went down." That is too simple. The codebase changed during the month, and I had already fixed or reduced several classes of risk. The more interesting part was that the July run felt better calibrated. The findings clustered around practical application-security themes: public workflow abuse controls, safe rendering of metadata, and safer handling of URLs and filesystem writes in maintenance tooling. I am intentionally keeping that description high-level because the goal of this post is not to publish a playbook for the specific issues. [...] That may sound like a small UI change, but it made the scan easier to trust. Security reviews have a lot of quiet time. When the tool tells you what phase it is in, you spend less time wondering whether it is stuck and more time waiting for the right handoff point.

Paul Solt on X: "Codex can do bad things by accident. Back ...x.com · supporting

Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially

Tibo on X: "Hi! Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially destructive actions being performed by Codex during its work. A few weeks ago, we started investigating a small number of reports where GPT-5.6 in … / Xx.com · supporting

added clearer warnings, and further restricted especially risky permission combinations. - We updated Auto-review to better identify destructive actions. - We built targeted evaluations that replay the failures we observed. We’re also adding reinforcement-learning tasks and graders focused on these risks, and filtering destructive actions from training data. In those replay evaluations, the changes substantially reduced the behavior while preserving Codex’s ability to complete normal coding work. Two things to do on your end: - Keep the Codex app up to date. We are always improving safety, performance and many other things. - Use one of the sandbox modes: "Ask for approval" or "Approve for me". Only use Full access for environments you trust and can recover. Thanks and happy Codexing out [...] added clearer warnings, and further restricted especially risky permission combinations. - We updated Auto-review to better identify destructive actions. - We built targeted evaluations that repl