<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Openai on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/openai/</link><description>Recent content in Openai on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 19:08:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/openai/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenAI Codex Chains HTTP/2 DoS Attacks Autonomously</title><link>https://zxcloudsecurity.co.uk/posts/openai-codex-http2-dos-bomb-chained-attack/</link><pubDate>Thu, 04 Jun 2026 19:08:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/openai-codex-http2-dos-bomb-chained-attack/</guid><description>OpenAI&amp;#39;s Codex AI agent autonomously chained decade-old HTTP/2 DoS techniques to crash web servers in seconds — here&amp;#39;s what architects need to know.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/04/openais-codex-chains-decade-old-dos-techniques-into-http/2-bomb/5251377">The Register — Security</a></p>
<hr>
<p>OpenAI&rsquo;s Codex AI agent independently discovered and chained together multiple decade-old HTTP/2 denial-of-service techniques to bring down web servers within seconds, creating what researchers are calling an HTTP/2 bomb. This demonstrates that AI coding agents can autonomously rediscover and combine legacy attack methods into novel, highly effective exploits without human guidance. The incident raises significant concerns about the offensive security capabilities of large language model-based agents operating with minimal oversight.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your HTTP/2 implementation and ensure rate limiting, connection throttling, and request flood protections are in place at your load balancer or WAF layer — AWS WAF, Azure Front Door, and GCP Cloud Armor all offer relevant rule sets that should be validated against HTTP/2-specific DoS vectors. Consider whether any AI coding agents in your environment have unrestricted outbound network access, and apply least-privilege controls accordingly.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/04/openais-codex-chains-decade-old-dos-techniques-into-http/2-bomb/5251377">OpenAI&rsquo;s agent chained decade-old DoS attacks to crash web servers in seconds</a></p>
]]></content:encoded></item><item><title>OpenAI GPT-5.4 on AWS Bedrock GovCloud (US-West)</title><link>https://zxcloudsecurity.co.uk/posts/openai-gpt-5-4-amazon-bedrock-aws-govcloud-us-west/</link><pubDate>Wed, 03 Jun 2026 19:58:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/openai-gpt-5-4-amazon-bedrock-aws-govcloud-us-west/</guid><description>OpenAI GPT-5.4 is now available on Amazon Bedrock in AWS GovCloud (US-West), offering isolated inference for government and regulated-industry workloads.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/GPT54-available-in-aws-govcloud-us-west/">AWS What&rsquo;s New</a></p>
<hr>
<p>OpenAI&rsquo;s GPT-5.4 model is now generally available on Amazon Bedrock within AWS GovCloud (US-West), extending access to government and regulated-industry customers. The deployment leverages Bedrock&rsquo;s isolated inference infrastructure, ensuring prompts and responses remain within the customer&rsquo;s AWS environment and are not used for model training. This expands the options available for sensitive workloads requiring complex reasoning and document analysis under strict compliance controls.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Evaluate data residency and access control policies before enabling GPT-5.4 for sensitive workloads — confirm that Bedrock resource policies, VPC endpoints, and CloudTrail logging are configured to meet your organisation&rsquo;s compliance requirements, particularly if handling OFFICIAL-SENSITIVE or equivalent data in GovCloud.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/GPT54-available-in-aws-govcloud-us-west/">OpenAI GPT-5.4 generally available on Amazon Bedrock in AWS GovCloud (US-West)</a></p>
]]></content:encoded></item><item><title>UK Banks Excluded from Anthropic Glasswing AI Programme</title><link>https://zxcloudsecurity.co.uk/posts/uk-banks-excluded-anthropic-glasswing-openai-gpt-5-5-financial-sector/</link><pubDate>Wed, 03 Jun 2026 11:04:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/uk-banks-excluded-anthropic-glasswing-openai-gpt-5-5-financial-sector/</guid><description>Anthropic expands its Glasswing partner programme but excludes UK banks, while OpenAI offers GPT-5.5 access — implications for UK financial sector AI strat</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/03/anthropic-ups-glasswing-partner-count-4x-uk-banks-snubbed/5250450">The Register — Security</a></p>
<hr>
<p>Anthropic has expanded its Glasswing partner programme fourfold, inducting 150 new organisations including the first non-US members, while UK banks have notably been excluded from the initiative. In parallel, OpenAI is offering UK financial institutions access to GPT-5.5, highlighting a competitive dynamic in AI partnerships within the regulated financial sector. The exclusion raises questions around data sovereignty, regulatory compliance, and which AI vendors UK-regulated entities can practically partner with.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Cloud security architects at UK financial institutions should assess the compliance and data residency implications of both OpenAI and Anthropic offerings before committing to either platform, paying close attention to FCA and PRA guidance on third-party AI risk and ensuring any AI partnership agreements include robust contractual controls around data handling and model governance.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/03/anthropic-ups-glasswing-partner-count-4x-uk-banks-snubbed/5250450">UK banks offered access to OpenAI’s GPT-5.5 amid exclusion from Anthropic’s Glasswing expansion</a></p>
]]></content:encoded></item><item><title>UK Banks Snubbed by Anthropic Glasswing, Offered OpenAI GPT-</title><link>https://zxcloudsecurity.co.uk/posts/uk-banks-anthropic-glasswing-exclusion-openai-gpt-5-5/</link><pubDate>Wed, 03 Jun 2026 11:04:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/uk-banks-anthropic-glasswing-exclusion-openai-gpt-5-5/</guid><description>Anthropic expands its Glasswing AI partner programme but excludes UK banks. OpenAI steps in with GPT-5.5 access. What this means for financial sector secur</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/03/anthropic-ups-glasswing-partner-count-4x-uk-banks-snubbed/5250450">The Register — Security</a></p>
<hr>
<p>Anthropic has expanded its Glasswing partner programme fourfold, inducting 150 new organisations including the first non-US members, while UK banks have notably been excluded. OpenAI has moved to fill the gap by offering UK financial institutions access to GPT-5.5. The development highlights growing competitive dynamics in enterprise AI access and raises questions about supply chain concentration risk for financial sector security teams.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Cloud security architects in UK financial services should assess the security posture, data residency commitments, and compliance certifications of any AI provider they are offered as an alternative — do not treat OpenAI&rsquo;s GPT-5.5 access as a like-for-like replacement for Anthropic without conducting due diligence on API security controls, data handling agreements, and regulatory alignment with FCA/PRA expectations.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/03/anthropic-ups-glasswing-partner-count-4x-uk-banks-snubbed/5250450">UK banks offered access to OpenAI’s GPT-5.5 amid exclusion from Anthropic’s Glasswing expansion</a></p>
]]></content:encoded></item></channel></rss>