# ox.security > AI-optimized mirror of ox.security containing 50 pages totalling 40,575 words of clean markdown content, structured data, and semantic HTML. Original source: https://ox.security. Last updated: 2026-09-07T03:52:49.633Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Prompt to Runtime Application Security | OX Security](/content/site-root.html): Accelerate the transition to software that secures itself. OX Security pinpoints risk to the exact line of code, eliminating security debt from AI generation to cloud runtime. (853 words) ## Articles & Blog Posts - [AuditBoard Case Study: $1M Cost Savings & 98% Fewer False Positives | OX Security](/content/customer-stories/how-auditboard-automated-appsec-noise-reduction-and-saved-1m-with-a-unified-platform.html): Learn how AuditBoard automated risk reduction, saved 40 hours of manual work weekly, and avoided $1M in costs by consolidating AppSec tools with OX Security. (949 words) - [How Kaltura Accelerated Engineering Velocity and Slashed Security Noise by 80% | OX Security](/content/customer-stories/kalturas-journey-to-streamlined-development-with-ox-security.html) (813 words) - [eBlu Solutions Case Study: 70% Reduction in Security Overhead | OX Security](/content/customer-stories/how-eblu-solutions-automated-data-protection-and-slashed-security-overhead-by-70.html): How eBlu Solutions automated healthcare data protection and slashed manual security overhead by 70% to remediate vulnerabilities in hours, not weeks. (1,031 words) - [Swisscom Case Study: Zero Critical Vulnerabilities & 95% Noise Reduction | OX Security](/content/customer-stories/securing-the-ai-native-era-how-swisscom-achieved-zero-critical-vulnerabilities-with-ox-security.html): See how Swisscom achieved a 95% reduction in critical findings and reached zero critical vulnerabilities for the first time by using OX Security’s AI-native platform. (775 words) - [CyberTech Global IL | OX Security](/content/events/cybertech-global-il/index.html): OX Security joins the annual Cybertech Global event in Tel Aviv, showcasing OX Active ASPM's prowess in combating false positives and SDLC security issues. Discover how our solutions deliver decisive advantages in cybersecurity. (30 words) - [All in One Application Security Platform | OX Security](/content/dp/all-in-one-application-security-platform/index.html) (451 words) - [JFROG SwampUP 2024 | OX Security](/content/events/jfrog-swampup-2024/index.html): Attend the Third Party SCCS Summit with OX Security to learn about securing third-party software supply chains & managing cyber risks (27 words) - [2024 Americas Fall Summit | OX Security](/content/events/2024-americas-fall-summit/index.html): Attend the 2024 Americas Fall Summit with OX Security to discuss the latest trends & innovations in cybersecurity & application security. (27 words) - [Global MaaS Leader Case Study: 90% Reduction in Alert Noise | OX Security](/content/customer-stories/how-a-global-maas-leader-eliminated-alert-fatigue-and-mapped-runtime-exposure-to-source-with-ox.html): Explore how a global leader in Mobility-as-a-Service eliminated alert fatigue by mapping runtime exposure back to source code with OX Security. (719 words) - [Third Party & SCCS Summit & SCCS Summit | OX Security](/content/events/third-party-sccs-summit/index.html) (34 words) - [888 Holdings Case Study: Centralizing Global AppSec at Scale | OX Security](/content/customer-stories/how-888-holdings-centralized-global-security-and-accelerated-remediation-at-scale.html): See how 888 Holdings achieved a single source of truth for global security and transformed dashboards into dynamic process enhancers with OX Security. (694 words) - [InfoSecurity Europe | OX Security](/content/events/infosecurity-europe/index.html): Visit us at Info Security London, Stand #B126, to discover how OX Security can enhance your organization's application security. Learn about our innovative solutions including Attack Path Analysis, BOM Overview (SBOM, SaaS BOM, API BOM), AppSec Data Fabric, Automated Remediation, and Contextualized Prioritization. (27 words) - [OWASP Global AppSec San Francisco | OX Security](/content/events/owasp-global-appsec-san-francisco/index.html): Join us at OWASP Global AppSec at Hyatt Regency, San Francisco, from September 23-27. Discover how OX Security leads the way in application security innovation. Learn about our advanced solutions that effectively combat threats and streamline security operations. (33 words) - [Black Hat Europe 2024 | OX Security | Register](/content/events/black-hat-europe-2024/index.html): OX Security is heading to Black Hat Europe 2024! Join us at ExCel London on December 11-12 to revolutionize your application security. Discover advanced solutions and strategies designed to enhance your AppSec defenses. Don't miss this opportunity to connect with our experts and explore cutting-edge cybersecurity innovations. (29 words) - [OWASP Global AppSec EU 2025 | OX Security](/content/events/owasp-barcelona/index.html) (30 words) - [Kaltura Case Study: Total Supply Chain Visibility in 5 Minutes | OX Security](/content/customer-stories/how-kaltura-achieved-total-supply-chain-visibility-in-minutes.html): See how Kaltura gained total supply chain visibility in 5 minutes and secured their software pipeline by replacing manual triage with the OX Platform. (597 words) - [Cybersec Europe | OX Security](/content/events/cybersec-europe/index.html) (24 words) - [Gitex Berlin | OX Security](/content/events/gitex-berlin/index.html) (26 words) - [DoubleVerify Case Study: Eliminating Fragmented AppSec Tools | OX Security](/content/customer-stories/doubleverify-gains-control-and-efficiency-with-ox-security.html): Discover how DoubleVerify gained a clear, prioritized view of its applications and accelerated remediation without manual work using the OX Security platform (696 words) - [Grand IT Cyber Security | OX Security](/content/events/grand-it-cyber-security/index.html) (25 words) - [The Ultimate App Security Blog | OX Security](/content/blog/index.html): Learn about the latest developments in application security posture management (ASPM), DevSecOps tools, and software supply chain security. (194 words) - [Application Security Tools Marketplace | OX Security](/content/security-tools-marketplace/index.html): OX Security provides single-click Integration with development environments and commercial security tools, allowing DevSecOps to consolidate appsec tools. (111 words) - [Job opportunity: Security Research (B2B Contract)](/content/careers-position/co/emea/4d-b63/security-research-b2b-contract/all/index.html): Ox Security secures the AI-driven SDLC from prompt to production. We eliminate critical, real-time risks from AI code generation through cloud runtime by doing what conventional tools can’t: unifying development and cloud context to stop vulnerabilities right at the source. At OX, we’re building the future of cyber security for the AI era. If you’re looking to work on disruptive technology with an amazing team, you belong here.We're looking for a highly skilled and driven Security Researcher to join our research group to analyze supply chain attacks, dissect malware, and build open-source tools. This is a high-impact role where you'll work with cross-functional teams to help scan and protect users and organizations around the world from the hottest cyber threats, playing a key part in shaping the future of OX. (481 words) - [Join OXIGEN: The OX Alliance Partner Program | OX Security](/content/technology-alliances/index.html): Accelerate your growth with the OXIGEN Alliance Partner Program. Build deep technical integrations, unlock joint pipelines, and co-sell with OX Security. (253 words) - [ClickFix Phishing Hidden in Malicious npm Packages](/content/blog/research-clickfix-phishing-npm-packages/index.html): OX Research uncovered dozens of malicious npm packages using trusted mirror sites like unpkg to host fake CAPTCHA pages that redirect victims to ClickFix phishing infrastructure. (910 words, Aug 25, 2026) - [GitLab GraphQL CVEs: CVE-2026-19478 & CVE-2026-19650](/content/blog/gitlab-graphql-cve-2026-19478-19650/index.html): Two critical GitLab GraphQL flaws (CVE-2026-19478, CVE-2026-19650) let unauthenticated attackers modify or delete public projects. Self-managed instances need to upgrade now. (1,272 words, Aug 18, 2026) - [A New Infostealer Worm Hits npm, affecting Keyv and Cacheable](/content/blog/a-new-infostealer-worm-hits-npm-affecting-keyv-and-cacheable.html): Breaking News: A Shai-Hulud Campaign hits npm. +350 Packages Compromised, Over 2B Monthly Downloads Affected (3,263 words, Aug 4, 2026) - [Malware-Slop: Malicious npm Package Leaks Telegram Bot Token](/content/blog/malware-slop-2-malicious-npm-package-leaks-its-own-bots-telegram-private-token.html): OX Security discovers cms-store-ren, a malicious infostealer on npm that leaked its own threat actor Telegram bot API token (609 words, Jun 4, 2026) - [AI Security Testing: Validate LLMs, Agents & Pipelines](/content/blog/ai-security-testing/index.html): Learn to validate LLMs and AI agents in production. Covers prompt injection testing, tool execution risks, and building a repeatable AI security harness. (4,371 words, May 28, 2026) - [From Auth Bypass to RCE: DataEase 4-Vulnerability Exploit Chain](/content/blog/from-auth-bypass-to-rce-a-4-vulnerability-exploit-chain-in-dataease.html): OX Research discovered three vulnerabilities in DataEase that chain together with a previously disclosed bypass to achieve RCE. (1,322 words, May 25, 2026) - [The Shai-Hulud npm malware returns with 320+ affected packages](/content/blog/the-antv-ecosystem-was-compromised-with-shai-hulud-malware-300-packages-affected.html): The @antv Ecosystem Was Compromised with Shai-Hulud Malware. Learn how to protect your credentials from TeamPCP’s latest supply chain attack. (1,774 words, May 19, 2026) - ["Shai-Hulud" Malware Hits 170+ npm & PyPi Packages](/content/blog/shai-hulud-here-we-go-again-170-packages-hit-across-npm-pypi.html): Breaking: Shai-Hulud malware targets 170+ npm & PyPi packages. Learn how to protect your software supply chain (1,891 words, May 12, 2026) - [MCP STDIO Command Injection: Full Vulnerability Advisory](/content/blog/mcp-supply-chain-advisory-rce-vulnerabilities-across-the-ai-ecosystem.html): OX Security's full disclosure advisory for command injection vulnerabilities in MCP STDIO configurations, covering 10 CVEs (2,041 words, Apr 15, 2026) - [Malicious LiteLLM Packages Steal AWS & Crypto Keys](/content/blog/litellm-malware-malicious-pypi-versions-steal-cloud-and-crypto-credentials.html): Malicious LiteLLM versions on PyPI steal AWS, GitHub, and crypto credentials. Rotate keys now if affected. (423 words, Mar 24, 2026) - [OpenClaw Developers Targeted in Crypto-Wallet Phishing Attack](/content/blog/openclaw-github-phishing-crypto-wallet-attack/index.html): A phishing campaign targeting GitHub developers uses a fake OpenClaw site to steal crypto wallets. OX Security details the attack and how it works. (844 words, Mar 18, 2026) - [CVE-2025-11158: Critical RCE in Pentaho Puts Enterprises at Risk](/content/blog/cve-2025-11158/index.html): Critical zero-day RCE vulnerability in Pentaho (CVE-2025-11158) affecting all versions up to 10.2.0.6. 2,600+ exposed instances. Patch now. (970 words, Mar 10, 2026) - [CVE-2025-65715: Code Runner VS Code RCE Vulnerability](/content/blog/cve-2025-65715-code-runner-vscode-rce/index.html): Technical Analysis of CVE-2025-65715: high-severity vulnerability in the Code Runner VS Code extension that enables remote code execution (507 words, Feb 17, 2026) - [You Can't Just "Delete" OpenClaw: How to Actually Uninstall It](/content/blog/how-to-uninstall-openclaw-remove-data-revoke-access.html): OX Security shows that uninstalling OpenClaw leaves sensitive data behind. Follow these steps to remove credentials and revoke access. (1,197 words, Feb 4, 2026) - [One Step Away From a Massive MoltBot Data Breach](/content/blog/one-step-away-from-a-massive-data-breach-what-we-found-inside-moltbot.html): MoltBot (OpenClaw) flaws expose 300k+ users: cleartext credentials, supply chain risks, and insecure code patterns discovered by OX Security. (1,917 words, Jan 29, 2026) - [Top 5 Vulnerability Scanning Tools for Enterprise Leaders](/content/blog/vulnerability-scanning-tools/index.html): Discover the top 5 vulnerability scanning tools trusted by enterprise product security leaders to identify risks, improve security posture, and scale protection. (899 words, Jan 26, 2026) - [Malicious Chrome Extensions Steal ChatGPT Conversations](/content/blog/malicious-chrome-extensions-steal-chatgpt-deepseek-conversations.html): OX Security discovered malicious Chrome extensions stealing ChatGPT and DeepSeek conversations from 900K users. One received Google's Featured badge. (733 words, Dec 30, 2025) - [Critical RCE Vulnerability in React & Next.js Exposed](/content/blog/rce-in-react-server-components/index.html): Unauthenticated RCE flaw in React (CVE-2025-55182) and Next.js lets attackers run privileged code on servers. Patch immediately. (901 words, Dec 3, 2025) - [Top 10 Application Security Testing Tools in 2026](/content/blog/application-security-testing-tools/index.html): Discover the best application security testing tools in 2026. Compare features, use cases, and integrations to secure code and scale AppSec across teams. (586 words, Sep 11, 2025) - [AI-generated Code: How to Protect Your Software From AI-generated Vulnerabilities | OX Security](/content/blog/ai-generated-code-how-to-protect-your-software-from-ai-generated-vulnerabilities.html): Explore actionable strategies and best practices to safeguard your code against the emerging risks of AI-generated vulnerabilities. (1,430 words, Apr 22, 2025) - [Elevating Software Supply Chain Security with OSC&R | OX Security](/content/blog/elevating-software-supply-chain-security-with-oscar.html): Five ways the OSC&R framework helps CISOs and AppSec leaders verify their software supply chain security. (905 words, Dec 13, 2023) - [IBM Ventures to Boost Software Supply Chain Security | OX Security](/content/blog/press-release-ox-security-receives-strategic-investment-from-ibm-ventures-to-supercharge-software-supply-chain-security.html): OX Security announced today that it received an investment from IBM the world's leading provider of enterprise open source solutions. (791 words, Aug 16, 2023) - [OX Security Now Available on AWS Marketplace | OX Security](/content/blog/ox-security-now-available-on-aws-marketplace/index.html): OX Security, the first and only end-to-end software supply chain security solution, has announced that it is now available on the AWS Marketplace. (368 words, May 2, 2023) - [What to Know About the Gartner Market Guide for CNAPPs | OX Security](/content/blog/what-you-need-to-know-from-the-garter-market-guide-for-cnapp.html): OX Security, the first end-to-end software supply chain security platform, is proud to be listed by Gartner as a Representative CNAPP Vendor. (752 words, Apr 5, 2023) - [4 Ways to Shield Your Software from Supply Chain Risks | OX Security](/content/blog/top-4-ways-to-protect-your-software-from-supply-chain-vulnerabilities.html): Let’s have a quick look at why software today is so vulnerable, then explore four ways you can keep your organization and your users safe. (970 words, Oct 18, 2022) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives - [AgentSite Network](https://agentsite.network/network.html): Public index of AgentSites and their machine-readable resources