OX Security

63 posts

OX Security banner
OX Security

OX Security

@OX__Security

Creator of VibeSec, the first platform to stop insecure AI-generated code before it exists | Fastest growing leader in Application and Product Security.

Katılım Haziran 2024
0 Takip Edilen60 Takipçiler
OX Security
OX Security@OX__Security·
Big results, less distraction. @auditboard cut 98% of irrelevant AppSec alerts with OX • 20–40 hours saved each week • Up to $1M in cost avoidance • Focused on real, reachable risks Full case study 👇 ox.security/case-study-aud…
English
0
0
0
57
OX Security retweetledi
Moshe Siman Tov Bustan
Moshe Siman Tov Bustan@MosheTov·
Time bomb techniques, obfuscation & encryption, targeting OS specific files and directories, crypto wallets, uses multi-stage decryption to execute each part of the attack in the right time... You can read our initial analysis on the @OX__Security blog: ox.security/blog/npm-worm-…
English
1
1
0
74
OX Security
OX Security@OX__Security·
The OX Research team has found vulnerabilities in 𝗳𝗼𝘂𝗿 popular IDE Extensions – confirming IDEs are the weakest link in an organization's supply chain security, bearing low exploit and high risk. ox.security/blog/four-vuln…
OX Security tweet media
English
0
0
2
55
OX Security
OX Security@OX__Security·
The @MunSecConf was a smashing success. Thank you to our amazing partners at the Economic and Trade Mission in Munich for the partnership and support throughout the delegation.
OX Security tweet mediaOX Security tweet media
English
0
0
0
41
OX Security retweetledi
Moshe Siman Tov Bustan
Moshe Siman Tov Bustan@MosheTov·
🚨 RCE ON vLLM! PATCH NOW! 🚨 A recently discovered vulnerability (CVE-2026-22778) in vLLM allows threat actors to send a malicious link to a vLLM service with the “video model” enabled in order to trigger an RCE, allowing complete takeover of the server! ox.security/blog/cve-2026-…
English
0
1
0
161
OX Security
OX Security@OX__Security·
Forbes quoted us. NBD. @realjoet cited our Army of Juniors report: AI code works, but lacks architectural judgment, prioritizes functionality over security, and the mythical 2 person LLM startup still does not exist. AI writes. Humans decide. forbes.com/sites/joetosca…
OX Security tweet media
English
0
1
1
58
OX Security
OX Security@OX__Security·
@Attila387637616 @howfxr @Attila387637616 Hey, the pattern seems to match but this is a different campaign seemingly from a different actor, there's no use of C2 uploads, only the reported Base64 info sent to the remote server.
English
1
0
0
25
Attila
Attila@Attila387637616·
@howfxr @OX__Security Have you guys seen .zst file uploads as part of this campaign? Pattern seems to match the research but this method is strange. Back from September to December.
English
1
0
0
22
OX Security retweetledi
ㆅ
@howfxr·
A malware campaign involving two Chrome extensions that impersonate a legitimate AI sidebar tool has been reported, according to @OX__Security! The extensions allegedly stole ChatGPT and DeepSeek conversations and browsing data.
ㆅ tweet media
English
3
1
5
132
OX Security
OX Security@OX__Security·
New research drop 🚨 A critical flaw in DataEase lets attackers brute-force admin access using weak JWT secrets, putting enterprise BI environments at serious risk. High severity, widely used open source tool, real-world exposure. ox.security/blog/blog-data…
English
0
0
0
77
OX Security
OX Security@OX__Security·
Spoiler: The 2026 version has better aim. 🕸️ Guess what? Attackers aren't chasing new tricks. They’re optimizing the basics. On Jan 27th see exactly how they’re doing it (and what we are doing to stop them). Save your spot: ox.security/webinar/threat…
OX Security tweet media
English
0
1
1
60
OX Security
OX Security@OX__Security·
Shift left sounds simple… until you actually try it. James Berthoty sat with us to talk about making security part of your coding flow, adding context, and ending up with better code without slowing you down. Watch the full conversation here: ox.security/webinar-regist…
English
0
0
0
51
OX Security
OX Security@OX__Security·
Is it 2015 again? Attackers aren’t chasing trends, they’re mastering the basics. In 2025, phishing, permissions, and supply chain leaks still win. Only difference: AI scales the same old playbook faster, while defenders chase buzzwords. Read more: thehackernews.com/2026/01/what-s…
English
0
0
0
43
OX Security
OX Security@OX__Security·
Attackers are upgrading. Again. 😅 We’ll look at the techniques gaining traction and some seriously cool findings from our research team. Most importantly, we're covering what you actually need to do about it all to keep secure. ox.security/webinar/threat…
OX Security tweet media
English
0
1
0
65
OX Security
OX Security@OX__Security·
It be like that sometimes
English
0
0
0
34
OX Security retweetledi
Shiv
Shiv@ishivtripathi·
@OX__Security discovered Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users The names of the extensions, which collectively have over 900,000 users, are below - Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI (ID: fnmihdojmnkclgjpcoonokmkhjpjechg, 600,000 users) AI Sidebar with Deepseek, ChatGPT, Claude, and more. (ID: inhcgfpbfdjbjogdfjbclgolkmhnooop, 300,000 users) Full Article: ox.security/blog/malicious…
English
0
1
1
110