OpenAI Codex chains old DoS techniques into HTTP/2 Bomb that crashes servers in seconds
An AI agent discovered a critical security flaw by combining two known attack methods. OpenAI Codex chained decade-old DoS attacks to create HTTP/2 Bomb, a new denial-of-service exploit that can render major web servers inaccessible within seconds using just a home computer. The attack affects nginx, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora, with some vendors still working on patches.