News
New Actors Deploy Shai-Hulud Clones: Team PCP Copycats Are Here
11+ hour, 5+ min ago (490+ words) These malicious packages contain infostealer malware, one of which is a Shai-Hulud clone following the Team PCP open source release, and one DDo S botnet package. Four new malicious npm packages were detected and reported by OX Security in the…...
New MCP Security Flaws: Kubectl-mcp-server, Archon OS, and Mark It Down Vulnerabilities
5+ day, 17+ hour ago (434+ words) TL; DR: The OX Research team discovered three vulnerabilities " two in widely used open-source MCPs and one in Archon OS, an open-source AI management platform. Two were assigned CVEs: CVE-2025-65719 and CVE-2025-69443. A third was rejected by Microsoft as working…...
Shai-Hulud, Here We Go Again: 170+ Packages Hit Across npm & Py Pi
5+ day, 20+ hour ago (270+ words) Shai-Hulud is a self spreading malware, which we extensively researched and wrote about due to its widespread impact. Recent attacks and infections included " Py Torch Lightning & Intercom-Client, SAP npm Packages, and Bitwarden CLI. This latest variant affecting Mistral AI, Open Search…...
AI Application Security in 2026: Real Risks and Controls
1+ week, 3+ day ago (1572+ words) AI application security is about securing how AI-powered software behaves in production, including the models it uses and the infrastructure it runs on. In large organizations, AI now shapes control flow, data access, and execution paths inside applications. As a…...
Cloud-native security best practices for enterprise platforms
1+ week, 4+ day ago (1758+ words) Security at this scale has to be in real-time, contextual, and built into the software delivery lifecycle, not bolted on after the fact. Google's Cybersecurity Forecast 2026 reinforces this trajectory. It highlights how adversaries will use AI to scale attacks and…...
8. 3 M Downloads Compromised: Lightning & Intercom-Client Infected in Latest Shai-Hulud Attack
2+ week, 3+ day ago (281+ words) Currently 2. 6. 2 and 2. 6. 3 are quarantined. Revert to 2. 6. 1 or lower. The Python package lightning was infected by a new Shai-Hulud variant uploaded to Py PI. The variant transforms from running Python to running Java Script, and deploys the same infostealer logic seen…...
Secure SDLC in the Age of AI: From Static Checks to Active Risk Control
2+ week, 6+ day ago (1582+ words) Your developers are already using AI to write code. Tools generate functions, dependencies, CI workflows, even infrastructure configurations in seconds. Software moves from idea to production faster than ever " but the security processes around it were designed for a very…...
Audit Board Case Study: $1 M Cost Savings & 98% Fewer False Positives
2+ week, 6+ day ago (235+ words) Phil Guimond, Senior Dev Sec Ops Engineer. "We've saved a lot of money by switching to OX because OX basically has a lot of different tools consolidated into one single dashboard," Phil Guimond explains. Audit Board's security team was trapped…...
Securing the AI-Native Era: How Swisscom Achieved Zero Critical Vulnerabilities with OX Security
2+ week, 6+ day ago (399+ words) "This marks the first time in our history that we've reached zero critical vulnerabilities" Colin Geisser, Lead Security Architect. Swisscom, a leading European telecommunications provider, confronted a modern engineering paradox: rapid AI adoption was accelerating software delivery, but it was…...
How e Blu Solutions Automated Data Protection and Slashed Security Overhead by 70%
2+ week, 6+ day ago (741+ words) OX Security How e Blu Solutions Automated Data Protection and Slashed Security Overhead by 70% "OX has drastically reduced the manual workload and uncertainty. It gives us the confidence that we're on top of any vulnerabilities as soon as they arise,…...