The Ultimate App Security Blog | OX Security

The OX Blog

April 15, 2026

The Mother of All AI Supply Chains: Critical, Systemic Vulnerability at the Core of Anthropic's MCP

-

-

- -

Moshe Siman Tov Bustan, Mustafa Naamnih, Nir Zadok, Roni Bar

August 30, 2026 4 ASPM Tools to Watch in 2026: Enterprise-Grade Features and Market Insights

Boaz Barzel

August 29, 2026 Shai-Hulud – Trinitite: Sponsored by Preview 2 Effects

Moshe Siman Tov Bustan

August 25, 2026 ClickFix Phishing Pages Discovered in 24 npm Packages

Moshe Siman Tov Bustan, Vitalii Chepurko

August 19, 2026 PBOM vs SBOM: What’s the Difference, and Why Does It Matter in 2026?

August 18, 2026 Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

Nir Zadok, Moshe Siman Tov Bustan

August 18, 2026 Critical vm2 Vulnerability Allows Host DNS Hijacking and Information Disclosure

Nir Zadok, Moshe Siman Tov Bustan

August 9, 2026 Shai-Hulud Outbreak Debrief: The Worm Evolves into MCP

Moshe Siman Tov Bustan

August 6, 2026 Did We Just Witness Step One of the Autonomous AI Arms Race?

Neatsun Ziv

August 6, 2026 CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions

Nir Zadok, Moshe Siman Tov Bustan