Please turn JavaScript on
Ox icon

Ox

Subscribe in seconds and receive Ox's news feed updates in your inbox, on your phone or even read them from your own news page here on follow.it.

You can select the updates using tags or topics and you can add as many websites to your feed as you like.

And the service is entirely free!

Follow Ox: OX Security | VibeSec Software Security Platform

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.6 / day

Message History

5 days after 440+ npm packages were compromised, 5 malicious repositories remain live in the wild—and the threat is still active

While the cybersecurity community was traveling to Black Hat last week, threat actors unleashed one of the most widespread software supply chain attacks of 2026. A new evolution of the Shai-Hulud self-propagating worm


Read full story
TL;DR

Application security posture management (ASPM) secures traditional applications, while AI security posture management (AI-SPM) protects AI models. In contrast, an AI-native application protection platform (AINAPP) is c...

Read full story
TL;DR Agentic AI security is the practice of protecting AI agents – and the LLMs, tools, and data sources they rely on – from threats like prompt injection, tool abuse, and identity attacks. Because AI agents operate as specialized programs that can carry out actions autonomously, often without having a human “in the loop” to validate their behavior, compromised agents ca...

Read full story
Frontier labs are catching autonomous models breaking containment. These aren’t isolated harness bugs—they’re the first observable data points of a system racing beyond our control.

If you see one mouse, there are more in the walls.

Frontier labs and safety institutions—including


Read full story
OX Research found and disclosed a Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin Vulnerability Details

CVE: CVE-2026-44613

Description: Apache Zeppelin’s default CORS configuration allowed cross-origin, credentialed, state-changing requests (and accepted text/plain request bodies), letting a remote attacker...


Read full story