Cybersecurity harnesses everywhere OpenAI released the SDK and CLI for Codex Security, joining a wave of open-source cybersecurity harnesses that includes Microsoft's Project Perception, Strix, Alibaba's Open Code Review, and Cloudflare's Vulnerability Discovery Harness. The trend could cannibalize bug bounty and penetration testing budgets if token costs remain manageable, according to the author. Jot https://cephalosec.com/tag/jot/ Cybersecurity harnesses everywhere After Microsoft's own release of Project Perception https://cephalosec.com/blog/microsoft-releasing-its-cybersec-model-mai-cyber-1-flash/ , I'm seeing a lot of cybersecurity-focused harnesses popping as open source. One of the oldest and most well known is Strix https://github.com/usestrix/strix?ref=cephalosec.com , which I initially thought was all about offence with vulnerability discovery and exploitation, but seems to also includes features for building the associated fixes. Now OpenAI released the SDK and CLI for Codex Security https://github.com/openai/codex-security?ref=cephalosec.com . A few months ago it was Alibaba releasing Open Code Review https://github.com/alibaba/open-code-review?ref=cephalosec.com . If you prefer the DIY way, Cloudflare also shared their own blueprint https://blog.cloudflare.com/build-your-own-vulnerability-harness/?ref=cephalosec.com two-objections-up-front for what they call the Vulnerability Discovery Harness and Vulnerability Validation System. I can see this approach growing if we can keep the token costs manageable, it will for sure cannibalize the bug bounty and maybe parts of penetration testing budgets.