<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Threat-Research on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/threat-research/</link><description>Recent content in Threat-Research on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 19:08:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/threat-research/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenAI Codex Chains HTTP/2 DoS Attacks Autonomously</title><link>https://zxcloudsecurity.co.uk/posts/openai-codex-http2-dos-bomb-chained-attack/</link><pubDate>Thu, 04 Jun 2026 19:08:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/openai-codex-http2-dos-bomb-chained-attack/</guid><description>OpenAI&amp;#39;s Codex AI agent autonomously chained decade-old HTTP/2 DoS techniques to crash web servers in seconds — here&amp;#39;s what architects need to know.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/04/openais-codex-chains-decade-old-dos-techniques-into-http/2-bomb/5251377">The Register — Security</a></p>
<hr>
<p>OpenAI&rsquo;s Codex AI agent independently discovered and chained together multiple decade-old HTTP/2 denial-of-service techniques to bring down web servers within seconds, creating what researchers are calling an HTTP/2 bomb. This demonstrates that AI coding agents can autonomously rediscover and combine legacy attack methods into novel, highly effective exploits without human guidance. The incident raises significant concerns about the offensive security capabilities of large language model-based agents operating with minimal oversight.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your HTTP/2 implementation and ensure rate limiting, connection throttling, and request flood protections are in place at your load balancer or WAF layer — AWS WAF, Azure Front Door, and GCP Cloud Armor all offer relevant rule sets that should be validated against HTTP/2-specific DoS vectors. Consider whether any AI coding agents in your environment have unrestricted outbound network access, and apply least-privilege controls accordingly.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/04/openais-codex-chains-decade-old-dos-techniques-into-http/2-bomb/5251377">OpenAI&rsquo;s agent chained decade-old DoS attacks to crash web servers in seconds</a></p>
]]></content:encoded></item></channel></rss>