56,966 blogs · [ { "id": "01a0e263-ee3d-730a-80dd-88c284a04d97", "title": "How MCP Is Bypassing a Decade of Cloud Security Best Practices", "url": "https://www.ox.security/blog/how-mcp-is-bypassing-a-decade-of-cloud-security-best-practices/", "published_at": "2026-09-24T09:00:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c285009e1c", "title": "How Do You Build Security for AI Agents That Don’t Exist Yet? ", "url": "https://www.ox.security/blog/how-do-you-build-security-for-ai-agents-that-dont-exist-yet/", "published_at": "2026-09-16T11:05:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c2851804c9", "title": "OX Security Launches OX Cloud, Redefining Cloud Security for the Agentic Era", "url": "https://www.ox.security/blog/ox-security-launches-ox-cloud-ai-agent-security/", "published_at": "2026-09-16T11:05:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c285f6985a", "title": "OX Cloud: CNAPP Coverage Plus Runtime Security for AI Agents", "url": "https://www.ox.security/blog/ox-cloud-cnapp-coverage-plus-runtime-security-for-ai-agents/", "published_at": "2026-09-16T10:37:56+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c286314e4b", "title": "Four Critical CVEs, the Same Trust Issue", "url": "https://www.ox.security/blog/four-critical-cves-the-same-trust-issue/", "published_at": "2026-09-14T08:27:46+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c2863c4867", "title": "Technical Analysis: Netty CVE-2026-75595, Next.js CVE-2026-75604, GHSA-2xp9-vwfh-vxw4 & GitPython CVE-2026-78676", "url": "https://www.ox.security/blog/technical-analysis-netty-cve-2026-75595-next-js-cve-2026-75604-ghsa-2xp9-vwfh-vxw4-gitpython-cve-2026-78676/", "published_at": "2026-09-14T08:05:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c28725d17d", "title": "Vet Every Dependency Your Agents Install with OX VibeSec", "url": "https://www.ox.security/blog/vet-every-dependency-your-agents-install-with-ox-vibesec/", "published_at": "2026-09-09T03:00:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c2877887ec", "title": "CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox", "url": "https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape/", "published_at": "2026-09-08T20:12:17+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c287df6369", "title": "4 ASPM Tools to Watch in 2026: Enterprise-Grade Features and Market Insights", "url": "https://www.ox.security/blog/aspm-tools/", "published_at": "2026-08-30T07:49:00+00:00" }, { "id": "01a0e263-ee3d-730a-80dd-88c287ead18c", "title": "Shai-Hulud – Trinitite: Sponsored by Preview 2 Effects", "url": "https://www.ox.security/blog/shai-hulud-trinitite-sponsored-by-preview-2-effects/", "published_at": "2026-08-29T07:50:58+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27d11fe32", "title": "ClickFix Phishing Pages Discovered in 24 npm Packages", "url": "https://www.ox.security/blog/research-clickfix-phishing-npm-packages/", "published_at": "2026-08-25T08:48:22+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27d2b7831", "title": "LiteLLM: an ordinary login token can become someone else’s admin account", "url": "https://www.ox.security/blog/litellm-an-ordinary-login-token-can-become-someone-elses-admin-account/", "published_at": "2026-08-24T12:29:00+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27dd3fec9", "title": "PBOM vs SBOM: What’s the Difference, and Why Does It Matter in 2026?", "url": "https://www.ox.security/blog/pbom-vs-sbom/", "published_at": "2026-08-19T14:19:15+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27ea9f08e", "title": "Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive", "url": "https://www.ox.security/blog/gitlab-graphql-cve-2026-19478-19650/", "published_at": "2026-08-18T15:27:50+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27f16e3da", "title": "Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure", "url": "https://www.ox.security/blog/critical-vm2-vulnerability-allows-host-dns-hijacking-and-information-disclosure/", "published_at": "2026-08-18T14:26:59+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27fab30ae", "title": "Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP", "url": "https://www.ox.security/blog/shai-hulud-outbreak-debrief-the-worm-evolves-into-mcp/", "published_at": "2026-08-09T19:51:32+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e27fda9d0a", "title": "Did We Just Witness Step One of the Autonomous AI Arms Race?", "url": "https://www.ox.security/blog/did-we-just-witness-step-one-of-the-autonomous-ai-arms-race/", "published_at": "2026-08-06T10:32:12+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e280855dad", "title": "CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions ", "url": "https://www.ox.security/blog/cve-2026-44613-turning-a-csrf-into-silent-unauthorized-actions/", "published_at": "2026-08-06T09:26:46+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e28180aeb8", "title": "A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads", "url": "https://www.ox.security/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable/", "published_at": "2026-08-04T12:09:18+00:00" }, { "id": "01a0e279-0a56-7189-a0a5-d6e28261f1bf", "title": "In the Mythos Age, 90% of Your Security Budget Protects the Wrong Layer", "url": "https://www.ox.security/blog/in-the-mythos-age-90-of-your-security-budget-protects-the-wrong-layer/", "published_at": "2026-07-28T11:00:00+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170a0339ee", "title": "OX Security Becomes First Prompt-to-Runtime Security Platform, Leading the Evolving AINAPP Category", "url": "https://www.ox.security/blog/ox-security-first-ainapp-platform/", "published_at": "2026-07-28T11:00:00+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170a2b2e59", "title": "OX Security Named a Sample Vendor Across Three Categories in the Gartner® Hype Cycle™ for Application Security, 2026", "url": "https://www.ox.security/blog/ox-security-named-a-sample-vendor-across-three-categories-in-the-gartner-hype-cycle-for-application-security-2026/", "published_at": "2026-07-28T09:22:06+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170afc067f", "title": "Shift Down, Not Just Left: Why Security Must Adapt to Agentic Era", "url": "https://www.ox.security/blog/shift-down-rethinking-devsecops-for-ai-coding-agents-ox-security/", "published_at": "2026-07-23T19:44:04+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170b5cc83b", "title": "CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server", "url": "https://www.ox.security/blog/cve-2026-63764-ssrf-in-lmdeploys-openai-compatible-api-server/", "published_at": "2026-07-22T12:06:57+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170b7fbe6f", "title": "CVE-2026-59873: Decompression DoS Via Unlimited Input In node-tar, 90M Weekly Downloads Affected", "url": "https://www.ox.security/blog/cve-2026-59873-decompression-dos-via-unlimited-input-in-node-tar-90m-weekly-downloads-affected/", "published_at": "2026-07-21T11:52:06+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170c133730", "title": "CVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution", "url": "https://www.ox.security/blog/cve-2026-3602-sql-injection-in-ibm-app-connect-enterprise-leads-to-code-execution/", "published_at": "2026-07-19T10:58:21+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170cb0defa", "title": "AsyncAPI npm organization compromised, 2M weekly downloads affected", "url": "https://www.ox.security/blog/asyncapi-npm-organization-compromised-2m-weekly-downloads-affected/", "published_at": "2026-07-14T10:28:46+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170cc673dd", "title": "Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials", "url": "https://www.ox.security/blog/malware-slop-crypto-stealer-impersonating-polymarket-exposes-its-own-credentials/", "published_at": "2026-07-12T11:14:26+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170d665593", "title": "Injectivelabs npm Package Hijacked, Impacting 87 Dependent Packages", "url": "https://www.ox.security/blog/injectivelabs-npm-package-hijacked-impacting-87-dependent-packages/", "published_at": "2026-07-09T15:46:22+00:00" }, { "id": "01a0e28b-f608-735b-988b-d4170e499a61", "title": "Malware Detected: Reverse Shell Without JavaScript Files in npm", "url": "https://www.ox.security/blog/malware-detected-reverse-shell-without-javascript-files-in-npm/", "published_at": "2026-07-05T12:30:10+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33a2eb6dd", "title": "Beyond CVSS Scores: The Enterprise Guide to Vulnerability Prioritization Tools That Actually Reduce Risk ", "url": "https://www.ox.security/blog/vulnerability-prioritization/", "published_at": "2026-07-01T10:47:53+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33a65859b", "title": "npm Is Fighting the Right War With the Wrong Weapons", "url": "https://www.ox.security/blog/npm-is-fighting-the-right-war-with-the-wrong-weapons/", "published_at": "2026-06-30T11:12:34+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33ab0dfe0", "title": "“Be Violent With Your Agents”: The Hard Truths of Governing Agentic AI", "url": "https://www.ox.security/blog/be-violent-with-your-agents-the-hard-truths-of-governing-agentic-ai/", "published_at": "2026-06-30T11:00:00+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33afcd6c9", "title": "AI Risk Management Frameworks Explained: Governance, Accountability, and Runtime Reality", "url": "https://www.ox.security/blog/ai-risk-management-framework/", "published_at": "2026-06-30T08:49:58+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33b1a2f45", "title": "AI is Rewriting the Rules of Software Security. Here’s What the Experts Say.", "url": "https://www.ox.security/blog/ai-is-rewriting-the-rules-of-software-security-heres-what-the-experts-say/", "published_at": "2026-06-25T16:21:13+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33c103476", "title": "“Alright Lets See If This Works”: Shai-Hulud / Miasma / Hades Variant Spreads on npm", "url": "https://www.ox.security/blog/alright-lets-see-if-this-works-shai-hulud-miasma-hades-variant-spreads-on-npm/", "published_at": "2026-06-25T06:10:55+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33ce85a83", "title": "OX Security is recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security", "url": "https://www.ox.security/blog/ox-security-is-a-leader-in-the-gartner-magic-quadrant-for-software-supply-chain-security/", "published_at": "2026-06-18T08:24:32+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33d3e0922", "title": "OX Security Joins Anthropic’s Cyber Verification Program", "url": "https://www.ox.security/blog/ox-security-anthropic-cyber-verification-program/", "published_at": "2026-06-17T14:28:07+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33de9d038", "title": "easy-day-js Supply Chain Attack Hits Mastra AI in npm", "url": "https://www.ox.security/easy-day-js-supply-chain-attack-hits-mastra-ai-in-npm/", "published_at": "2026-06-17T08:54:17+00:00" }, { "id": "01a0e295-b78c-7380-817f-f9c33eaa3520", "title": "AI Coding Security: Why the Vibe Coding Era Needs Guardrails", "url": "https://www.ox.security/blog/ai-coding-security-why-the-vibe-coding-era-needs-guardrails/", "published_at": "2026-06-16T16:19:39+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e760aa22c0", "title": "OX Security Wins Best DevSecOps Platform in The Hacker News’ Inaugural 2026 Cybersecurity Stars Awards", "url": "https://www.ox.security/blog/ox-security-wins-best-devsecops-platform-in-the-hacker-news-inaugural-2026-cybersecurity-stars-awards/", "published_at": "2026-06-11T19:26:13+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e7619961f4", "title": "Unify Application Risk, Drive Targeted Remediation with OX + Nucleus", "url": "https://www.ox.security/blog/unify-application-risk-drive-targeted-remediation-with-ox-nucleus/", "published_at": "2026-06-10T11:36:10+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e76223dbb0", "title": "OX Security Named a Sample Vendor in the Gartner® Hype Cycle™ for Secure Software Engineering, 2026", "url": "https://www.ox.security/blog/ox-security-named-a-sample-vendor-in-the-gartner-hype-cycle-for-secure-software-engineering-2026/", "published_at": "2026-06-04T19:45:48+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e762c2a036", "title": "Malware-Slop 2: Malicious npm Package Leaks Its Own Bot’s Telegram Private Token", "url": "https://www.ox.security/blog/malware-slop-2-malicious-npm-package-leaks-its-own-bots-telegram-private-token/", "published_at": "2026-06-04T19:13:08+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e763b876fc", "title": "600,000 Monthly Downloads Affected: Miasma Supply Chain Attack Is Back on npm", "url": "https://www.ox.security/blog/600000-monthly-downloads-affected-miasma-supply-chain-attack-is-back-on-npm/", "published_at": "2026-06-04T10:34:21+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e764301e40", "title": "IronWorm Supply Chain Malware Hits npm", "url": "https://www.ox.security/blog/ironworm-supply-chain-malware-hits-npm/", "published_at": "2026-06-03T20:01:36+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e764a8e9e6", "title": "Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated", "url": "https://www.ox.security/blog/six-stages-deep-and-an-endless-loop-shai-hulud-is-getting-sophisticated/", "published_at": "2026-06-02T13:14:15+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e76516b3ff", "title": "New Shai-Hulud hits npm: @redhat-cloud-services Compromised", "url": "https://www.ox.security/blog/new-shai-hulud-hits-npm-redhat-cloud-services-compromised/", "published_at": "2026-06-01T13:29:48+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e765693ce3", "title": "7 AI Security Testing Tools for LLMs, Agents, and AI Pipelines (2026)", "url": "https://www.ox.security/blog/ai-security-testing-tools/", "published_at": "2026-05-29T12:22:25+00:00" }, { "id": "01a0e2a5-b488-7354-85fc-f6e76657debc", "title": "AI Security Testing: How to Validate LLMs, Agents, and AI Pipelines in Production", "url": "https://www.ox.security/blog/ai-security-testing/", "published_at": "2026-05-28T07:21:33+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c884f94af9", "title": "Vibe Coding Security: Why 62% Of AI-Generated Code Ships With Vulnerabilities", "url": "https://www.ox.security/blog/vibe-coding-security/", "published_at": "2026-05-27T12:58:06+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c885481db5", "title": "The CVE Is Dead. Long live the Mythos Era.", "url": "https://www.ox.security/blog/the-cve-is-dead-long-live-the-mythos-era/", "published_at": "2026-05-27T11:27:45+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c885f4a032", "title": "Malware-Slop: New Malicious npm Package Leaks Its Own GitHub Private Token", "url": "https://www.ox.security/blog/malware-slop-new-malicious-npm-package-leaks-its-own-github-private-token/", "published_at": "2026-05-27T09:48:51+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c8864bd1d4", "title": "From Auth Bypass to RCE: A 4-Vulnerability Exploit Chain in DataEase", "url": "https://www.ox.security/blog/from-auth-bypass-to-rce-a-4-vulnerability-exploit-chain-in-dataease/", "published_at": "2026-05-25T11:48:42+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c886bfad9a", "title": "Megalodon: New CI/CD Malware Spreads Across GitHub, Infecting ~5,000+ Repositories", "url": "https://www.ox.security/blog/megalodon-cicd-malware-github/", "published_at": "2026-05-21T19:06:03+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c886c85530", "title": "The Complete Enterprise Guide to AI Code Security in 2026", "url": "https://www.ox.security/blog/ai-code-security/", "published_at": "2026-05-21T12:53:55+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c8878289fb", "title": "North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT", "url": "https://www.ox.security/blog/north-korean-npm-infostealer-rat/", "published_at": "2026-05-20T17:15:05+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c887b22260", "title": "TeamPCP Strikes (again): How a Trojan VS Code Extension Brought Down GitHub", "url": "https://www.ox.security/blog/teampcp-strikes-again-how-a-trojan-vs-code-extension-brought-down-github/", "published_at": "2026-05-20T13:48:00+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c888420288", "title": "AppSec is Alive: Runtime Cloud Security & A Night at the Museum", "url": "https://www.ox.security/blog/appsec-is-alive-runtime-cloud-security-a-night-at-the-museum/", "published_at": "2026-05-20T05:00:00+00:00" }, { "id": "01a0e2b7-3bbe-709b-bd9a-35c88857cbb7", "title": "SBOM Security in 2026: Why Inventory Alone No Longer Reduces Risk", "url": "https://www.ox.security/blog/sbom-security/", "published_at": "2026-05-19T10:20:28+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd642a2eeb4", "title": "Top 5 Runtime Security Tools for Application Runtime Protection in 2026", "url": "https://www.ox.security/blog/runtime-security-tools/", "published_at": "2026-05-19T08:43:10+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd642bbb2e0", "title": "CI/CD Security Can’t See What Your Pipeline Ships Without Code Changes", "url": "https://www.ox.security/blog/ci-cd-security/", "published_at": "2026-05-19T07:43:48+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd6431d9c69", "title": "The @antv Ecosystem Was Compromised with Shai-Hulud Malware, 300+ Packages Affected", "url": "https://www.ox.security/blog/the-antv-ecosystem-was-compromised-with-shai-hulud-malware-300-packages-affected/", "published_at": "2026-05-19T06:45:28+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd64399f0c8", "title": "New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here", "url": "https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/", "published_at": "2026-05-17T19:28:59+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd643cb87e0", "title": "From Prompt to Runtime: Four Ways to Find NGINX Rift (CVE-2026-42945) with OX Security", "url": "https://www.ox.security/blog/from-prompt-to-runtime-four-ways-to-find-nginx-rift-cve-2026-42945-with-ox-security/", "published_at": "2026-05-14T18:47:32+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd6445ef6d2", "title": "node-ipc npm Package Breached, Spreading Infostealer Malware", "url": "https://www.ox.security/blog/node-ipc-npm-package-infostealer-malware/", "published_at": "2026-05-14T17:53:54+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd644f7bcfd", "title": "Shai-Hulud Goes Open Source: Malware Creators Leak Their Own Code to GitHub", "url": "https://www.ox.security/blog/shai-hulud-open-source-malware-github/", "published_at": "2026-05-12T20:57:31+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd645de9877", "title": "New MCP Security Flaws: Kubectl-mcp-server, Archon OS, and MarkItDown Vulnerabilities", "url": "https://www.ox.security/blog/new-mcp-security-flaws-kubectl-mcp-server-archon-os-and-markitdown-vulnerabilities/", "published_at": "2026-05-12T11:59:00+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd646418e0f", "title": "CVE-2025-65719: Critical RCE in Kubectl MCP Server", "url": "https://www.ox.security/blog/cve-2025-65719-critical-rce-in-kubectl-mcp-server/", "published_at": "2026-05-12T11:59:00+00:00" }, { "id": "01a0e2ca-2c33-70fb-a52a-8bd646a991bd", "title": "MarkItDown MCP Exposes Developer Machines to File Theft ", "url": "https://www.ox.security/blog/markitdown-mcp-exposes-developer-machines-to-file-theft/", "published_at": "2026-05-12T11:59:00+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63b6f2e06", "title": "CVE-2025-69443: Archon OS Vulnerable To Unauthenticated Web-To-Client Attack", "url": "https://www.ox.security/blog/cve-2025-69443-archon-os-vulnerable-to-unauthenticated-web-to-client-attack/", "published_at": "2026-05-12T11:59:00+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63bd91240", "title": "“Shai-Hulud, Here We Go Again”: 170+ Packages Hit Across npm & PyPi", "url": "https://www.ox.security/blog/shai-hulud-here-we-go-again-170-packages-hit-across-npm-pypi/", "published_at": "2026-05-12T06:51:37+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63c2cfb8d", "title": "AI Application Security in 2026: Real Risks and Controls", "url": "https://www.ox.security/blog/ai-application-security/", "published_at": "2026-05-07T11:18:55+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63c682b3b", "title": "Cloud-Native Security Practices in 2026: A Strategic Guide for Enterprise Platforms", "url": "https://www.ox.security/blog/cloud-native-security-practices/", "published_at": "2026-05-06T12:11:35+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63ca1e65b", "title": "8.3M Downloads Compromised: Lightning & Intercom-Client Infected in Latest Shai-Hulud Attack", "url": "https://www.ox.security/blog/lightning-python-package-shai-hulud-supply-chain-attack/", "published_at": "2026-04-30T14:48:08+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63cd55510", "title": "Shai-Hulud Hits SAP: Stolen Credentials Found in 1,200 GitHub Repos", "url": "https://www.ox.security/blog/shai-hulud-sap-supply-chain-attack-npm/", "published_at": "2026-04-29T21:44:10+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63d1ff619", "title": "Flowise (CVE-2026-40933) & Upsonic (CVE-2026-30625): What to do when best practice isn’t enough? ", "url": "https://www.ox.security/blog/flowise-cve-2026-40933-upsonic-cve-2026-30625-what-to-do-when-best-practice-isnt-enough/", "published_at": "2026-04-27T19:20:43+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63d872650", "title": "Secure SDLC in the Age of AI: From Static Checks to Active Risk Control", "url": "https://www.ox.security/blog/secure-sdlc/", "published_at": "2026-04-27T11:33:11+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63dc24686", "title": "AI Security for AppSec: Securing AI-Generated Code at Scale", "url": "https://www.ox.security/blog/ai-security-for-appsec/", "published_at": "2026-04-25T11:15:38+00:00" }, { "id": "01a0e2df-2c05-7314-bf70-fec63e7d6f32", "title": "Securing the AI Supply Chain: How OX VibeSec Defends Against Anthropic MCP Vulnerability", "url": "https://www.ox.security/blog/anthropic-mcp-vulnerability-ox-vibesec-ai-supply-chain/", "published_at": "2026-04-24T17:08:35+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493215e8e82", "title": "Shai-Hulud: The Third Coming — Bitwarden CLI Backdoored in Latest Supply Chain Campaign", "url": "https://www.ox.security/blog/shai-hulud-bitwarden-cli-supply-chain-attack/", "published_at": "2026-04-23T14:11:02+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493216f191c", "title": "AI Security Tools for CI/CD Pipelines: What Actually Holds Up", "url": "https://www.ox.security/blog/ai-security-tools/", "published_at": "2026-04-23T10:45:51+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-249321c6dd11", "title": "Xinference allegedly hacked by TeamPCP, Malicious Package In PyPi", "url": "https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/", "published_at": "2026-04-22T15:18:54+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-249322a18054", "title": "Supply Chain Attack Hits Vercel: User Data is Being Sold on BreachForums For $2M", "url": "https://www.ox.security/blog/vercel-context-ai-supply-chain-attack-breachforums/", "published_at": "2026-04-20T15:01:03+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493230ef98a", "title": "The Mother of All AI Supply Chains: Technical Deep Dive", "url": "https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-technical-deep-dive/", "published_at": "2026-04-15T11:00:00+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493237582ee", "title": "The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic’s MCP", "url": "https://www.ox.security/blog/the-mother-of-all-ai-supply-chains-critical-systemic-vulnerability-at-the-core-of-the-mcp/", "published_at": "2026-04-15T11:00:00+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493244e945c", "title": "MCP Supply Chain Advisory: RCE Vulnerabilities Across the AI Ecosystem", "url": "https://www.ox.security/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem/", "published_at": "2026-04-15T10:41:00+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493252a90c4", "title": "Axios Compromised With A Malicious Dependency", "url": "https://www.ox.security/blog/axios-compromised-with-a-malicious-dependency/", "published_at": "2026-03-31T05:52:25+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-249326110159", "title": "TeamPCP’s Telnyx Windows Malware: Technical Analysis", "url": "https://www.ox.security/blog/teampcps-telnyx-windows-malware-technical-analysis/", "published_at": "2026-03-30T08:30:21+00:00" }, { "id": "01a0e2ef-d36f-700e-96ad-2493261ac3fd", "title": "Telnyx Malware: TeamPCP Strikes Again Following LiteLLM Compromise", "url": "https://www.ox.security/blog/telnyx-malware-teampcp-strikes-again-following-litellm-compromise/", "published_at": "2026-03-27T13:25:22+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f295358b", "title": "Critical Access Control Flaw in Apache Superset Exposes Sensitive Data to Unauthorized Users", "url": "https://www.ox.security/blog/https-www-ox-security-critical-access-control-flaw-in-apache-superset-exposes-sensitive-data-to-unauthorized-users/", "published_at": "2026-03-24T20:56:00+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f30b7589", "title": "LiteLLM PyPI Malware Steals Cloud, Crypto, Slack, and Discord Keys", "url": "https://www.ox.security/blog/litellm-malware-malicious-pypi-versions-steal-cloud-and-crypto-credentials/", "published_at": "2026-03-24T17:24:40+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f38a4eef", "title": "Known, Unpatched, Exploitable: Redash’s Python Sandbox Escape Gives Attackers Full Server Access", "url": "https://www.ox.security/blog/redashs-python-sandbox-escape-gives-attackers-full-server-access/", "published_at": "2026-03-24T09:25:00+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f4744c10", "title": "3 Years Later, CVE-2023-38646 Still Haunts Thousands of Metabase Deployments", "url": "https://www.ox.security/blog/3-years-later-cve-2023-38646-still-haunts-thousands-of-metabase-deployments/", "published_at": "2026-03-24T09:06:00+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f4f0e649", "title": "Bridge the Code-to-Cloud Gap and Neutralize Real Risk with OX + Tenable", "url": "https://www.ox.security/blog/bridge-the-code-to-cloud-gap-and-neutralize-real-risk-with-ox-and-tenable/", "published_at": "2026-03-19T10:06:37+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f56d0fdf", "title": "OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack", "url": "https://www.ox.security/blog/openclaw-github-phishing-crypto-wallet-attack/", "published_at": "2026-03-18T17:35:25+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f65e3653", "title": "OX Agentic Pentester – Closing the Loop on AppSec Risk", "url": "https://www.ox.security/blog/ox-agentic-pentester-closing-the-loop-on-appsec-risk/", "published_at": "2026-03-12T15:41:10+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f67aaae3", "title": "OX Supercharges AI Coding with Cursor Hooks", "url": "https://www.ox.security/blog/ox-supercharges-ai-coding-with-cursor-hooks/", "published_at": "2026-03-12T10:36:41+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f77918dd", "title": "CVE-2025-11158: Critical RCE Found in Widely-Deployed Pentaho Platform, Putting Enterprise BI at Risk  ", "url": "https://www.ox.security/blog/cve-2025-11158/", "published_at": "2026-03-10T12:58:20+00:00" }, { "id": "01a0e303-d8eb-7196-9398-6331f82a1783", "title": "Mail2Shell – CVE-2026-28289: New Zero-Click RCE On FreeScout", "url": "https://www.ox.security/blog/freescout-rce-cve-2026-28289/", "published_at": "2026-03-03T18:23:23+00:00" } ] posts Claim your blog
Back to ox.security
Blog · corpus.blog/blogs/ox.security/posts

ox.security

ox.security

2026