The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp.
GPT-5.6 was already running in Codex for some users before OpenAI’s government-approved preview opened to partners. A ...