@OX__Security

Securing your applications from Prompt to Runtime.

Joined June 2024
🚨 AI changed how software gets built. Security is still playing catch-up. Agents now write code, connect to tools, provision infrastructure, and execute workflows in real time—while AppSec and CNAPP remain built for a human-led world. OX Security is the first prompt-to-runtime platform built to secure the full agentic development lifecycle, defining the emerging AINAPP category. The Mythos Age needs a new security model. OX built it. ➡️ ox.security/blog/ox-security… -- #AINAPP #AISecurity #CyberSecurity
3
1
9
421
What would you do if your enterprise data was reaching a private home network in China? Or a server in Russia? Read our full report → ox.security/ebooks/15465-mcp… New OX Security research shows how agentic workflows can bypass cloud security governance built for a very different era. 15,465 MCP servers. 0 governance. #CloudSecurity #MCP #AISecurity
2
4
86
Security research, but make it a world tour. 🎸💻 OX Research Team Lead @MosheTov is hitting the road for a run of speaking engagements this fall: 10/03 @BSidesTO — Toronto, Canada 10/14 @InfoSec_World — Orlando, FL 11/04 @RBLN26 — San Francisco, CA 11/05 @Owasp — San Francisco, CA More details on each stop coming in the weeks ahead🤘
1
4
422
We’re building security for today’s AI agents. That may already be the wrong target. Read @neatsun's latest on Agentic Darwinism → ox.security/blog/how-do-you-… Agents are gaining more autonomy, more context, greater reach, and more authority to act. What exists today is just one stage in that evolution. #AgenticAI #AISecurity #AgenticDarwinism
1
2
70
Jack Sparrow explains cloud security?? ☁️ We do it better 🏴‍☠️ Learn more → ox.security/blog/ox-cloud-cn… #CloudSecurity #AISecurity #AINAPP
2
59
Your cloud isn’t just running infrastructure anymore. It’s running agents. 🤖☁️ See what’s new with OX Cloud → ox.security/blog/ox-cloud-cn… Posture management + live AI detection + deep runtime inspection + reachability to show what’s running, what it’s doing, and what actually matters. The runtime pillar of OX AINAPP. From prompt to runtime. #CloudSecurity #AINAPP #AISecurity
61
when the prompt actually works on the first try…
Allison Janney's reaction to winning the Emmy for Best Supporting Actress in a Drama Series.
2
117
🚨 4 Critical CVEs. 24 Hours. One Mistake: Blind Trust. FULL REPORT: ox.security/blog/four-critic… Last week, four critical vulnerabilities landed across Next.js, Netty, and GitPython. All four are remotely reachable. All four require no authentication. Three sit in code paths enabled by default. Different products. Different bugs. Same failure: one component trusted the layer next to it. → Next.js: RCE + sensitive data exposure → Netty: mTLS bypass → GitPython: config injection → RCE Patched versions are available for all four. #CyberSecurity #CVE #AppSec
1
3
180
ChatGPT: "trust me, the code is secure” 🫠 #AI #AppSec #SecureCoding
4
123
🚨 One command let a DeepSeek Harness AI agent disable its own file sandbox. Attacker-supplied text could push the agent to call the tool’s local interface, switch to danger-full-access, and remove approval prompts. Read: thehackernews.com/2026/09/de…
14
24
2
84
26,260
what actually cuts through the noise right now? at #BHUSA, @chasgold spoke with OX's Jillian Jones about what actually stands out when everyone starts sounding the same. her take: a little less polish, a little more personality, and the willingness to challenge the consensus. read the full piece: sequel.io/blog/authenticity-… #Cybersecurity #CyberMarketing #BlackHat
1
2
93
🚨 One command. The AI agent turns off its own sandbox. OX Research disclosed CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness. FULL REPORT: ox.security/blog/cve-2026-82… No creds. No network exposure. Shipped defaults. A confined agent could elevate itself to 'danger-full-access' #CyberSecurity #AISecurity #CVE
1
6
188
🚨 AI AGENTS IN DEEPSEEK HARNESS CAN DISABLE THEIR OWN SANDBOX 🚨 CVE-2026-82533, CVSS 9.4, DeepSeek Harness (dsh). 215,000+ GitHub stars, fastest growing repo. One. curl. command. = sandbox escape. 🤯 The harness ships an OS sandbox so a coding agent working on untrusted material can't reach your machine. DeepSeek did everything right, they just forgot that the agent inside sandbox can communicate with the host machine via localhost, oh, and they also forgot that you can tell the localhost to... DISABLE THE SANDBOX 🤦 And it's not just that it escaped, the logs show that the commands the agents send - are logged as the user itself, "source": {"kind": "user"} - meaning that the harness couldn't tell its own agent's shell from a real user that's typing them. Our team disclosed the vulnerability on Aug 24, and the issue was fixed on Aug 27 on 0.1.2-alpha.1. Recommended Actions: - Upgrade to 0.1.2-alpha.1 or later Read the full blog: ox.security/blog/cve-2026-82…
2
16
2
34
2,473
Excited to share that I'll be speaking at BSides Toronto! Catch my talk, "One IDE to Rule Them All - Securing Your Supply Chain's Weakest Link," on Oct 3rd. And if you're in the Toronto area around then, let's meet up!
4
2
1
12
627
London, this one’s for you 🌅 We're hosting an exclusive yacht soirée on the Thames 🍖 Premium BBQ 🍹 Signature cocktails 🎧 Live DJ & curated music ✨ Relaxed networking and great vibes Request to join: luma.com/London-Yacht-event-… - #CyberSecurity #London #AppSec
1
115
🚨 Less than 24 hours after the TeamPCP arrests, a new Shai-Hulud variant hit npm. Over the weekend, OX Research uncovered “Trinitite” spreading through a package with 128K+ weekly downloads. FULL REPORT: ox.security/blog/shai-hulud-… - #CyberSecurity #SupplyChainSecurity #npm
2
2
3
452
there can only be one OX 👊 #OxAlpha #AI #AppSec
1
3
135
OX Research uncovered 24 malicious npm packages abusing npm mirrors to host fake Cloudflare pages and redirect users to attacker-controlled infrastructure. And the story is making headlines 🗞️ @BleepinComputer - bleepingcomputer.com/news/se… @TheHackersNews - thehackernews.com/2026/08/24… @Cybernews - cybernews.com/security/hacke… ...and more! thank you for amplifying our research & fighting the good fight 🤘 #CyberSecurity #npm #SoftwareSupplyChain
4
8
356
Amsterdam. Ajax vs PSV. OX. ⚽ We’re bringing together a select group of security and technology leaders for an exclusive evening at Johan Cruijff Arena on September 5. Request to join: luma.com/OXinamsterdam Hosted late lunch. Premium match seating. Executive networking around one of European football’s biggest rivalries. #CyberSecurity #AppSec #Amsterdam
2
402
🚨 Trusted npm mirrors turned into phishing infrastructure. We found 24 malicious npm packages hosting fake Cloudflare verification pages on legitimate mirror domains. Trust becomes the weapon. FULL REPORT: ox.security/blog/research-cl… --- #CyberSecurity #SupplyChainSecurity #npm
1
3
7
250