FEED
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions
A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads
CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server
CVE-2026-59873: Decompression DoS Via Unlimited Input In node-tar, 90M Weekly Downloads Affected
Breaking: OX Research is tracking active threats across the AI software supply chain
Breaking: OX Research is tracking active threats across the AI software supply chain
Breaking: OX Research is tracking active threats across the AI software supply chain
Breaking: OX Research is tracking active threats across the AI software supply chain
Research News
Cybersecurity news, research, and threat intelligence from OX Security
Breaking news
Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP
5 days after 440+ npm packages were compromised, 5 malicious repositories remain live in the wild—and the threat is still active While the cybersecurity community was traveling to Black Hat last week, threat actors unleashed one of the most widespread…
Read Full Report
ALL RESEARCH
A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads
Read
CVE-2026-63764: SSRF in LMDeploy’s OpenAI-Compatible API Server
ReadNo research matches your filters.