Securing your applications from Prompt to Runtime.

Joined June 2024
82 Photos and videos
OX Security retweeted
5 days, 120 CISOs from around the globe, one Village. I was proud to take part in Team8 CISO Village Summit 2026, a gathering that reminded me why this community matters so much. We spent the week discussing AI, nation-state threats, insider risk, identity, exposure management, resilience, and the changing role of the CISO, but the real value was not only in the agenda. It was in the trust built among people facing the same hard questions from different angles. AI is reshaping cybersecurity, no doubt. It is changing how attackers move, how defenders respond, how software is built, and how risk is understood. But the strongest lesson from this week was that in the age of machines, the human network becomes even more important. The open conversations, the shared lessons, the uncomfortable questions, the willingness to say what is really happening inside our organizations, that is what turns a group of leaders into a Village. Thank you, Team8 CISO Village, for bringing together an extraordinary community of security leaders. In a world moving faster than any one organization can handle alone, the Village is not just a community. It is part of the defense. It takes a Village. #Team8CISOVillage @team8group
1
2
53
โณ LESS THAN 4 DAYS AWAY โ€ผ๏ธ Join security leaders & practitioners from @awscloud, @Poshmarkapp, @mondaydotcom, @AlphaSenseInc, @fastly, @latiotech, @rain_capital and... be part of the conversation shaping the future of security. ๐Ÿ”—ย ox.security/vibeseccon-retโ€ฆ ๐Ÿ“… Tues - June 16, 2026 โฐ 12PM ET | 9AM PT | 6PM CEST
42
The Mythos Era isn't defined by more CVEs โ€” it's defined by understanding how vulnerabilities connect, compound, and evolve into exploitable attack paths. Join us as we unpack the emerging patterns shaping the AI-driven threat landscape: ๐Ÿ”ฌ ๐‘๐ž๐ฌ๐ž๐š๐ซ๐œ๐ก ๐’๐ž๐ฌ๐ฌ๐ข๐จ๐ง From Standalone CVEs to Exploit Chains: What the CVE Flood Actually Means featuring @OX__Security's very own: โšก @MosheTov | Security Research Team Leader โšก Matt Hines | Head of Product Marketing ox.security/vibeseccon-returโ€ฆ โŒ› ONLY 4 DAYS LEFT TO REGISTER โŒ›
1
3
128
๐Ÿ”ฅHOT TAKE >> will one platform rule them all? is it the future of cybersecurity? or is it a convenient myth? we asked Kevin Jackson, CEO @Level6Cyber, for his take โ€” and his answer may surprise you! #CyberSecurity #AppSec #PlatformEngineering #RSAC
1
2
4
101
๐Ÿ† OX Security has been named the Best DevSecOps Platform in the Cybersecurity Stars Awards 2026! Huge thanks to @TheHackersNews for the recognitionย ๐Ÿ™Œ Proud to be helping organizations unify AppSec, prioritize real risk, and accelerate remediationย โšก FULL ARTICLE: awards.thehackernews.com/winโ€ฆ #CyberSecurity #AppSec #DevSecOps
4
14
8,741
AI is reshaping software development, forcing organizations to balance innovation, governance, and security while managing the growing risks that come with increased speed, automation, and scale. join the security leaders at the forefront of AI adoption as they discuss the real-world tradeoffs between innovation, governance, and risk: ๐Ÿ› ๏ธ ๐Ž๐ฉ๐ž๐ซ๐š๐ญ๐ข๐จ๐ง๐š๐ฅ ๐’๐ž๐ฌ๐ฌ๐ข๐จ๐ง Balancing Speed and Safety: Untangling the AI Security Tradeoff ๐Ÿš€ @begimher | Sr. Security Engineer, @awscloud ๐Ÿš€ @JamesBerthoty | Founder & CEO, @latiotech ๐Ÿš€ @pmungse | Head of Security, @Poshmarkapp โšก Moderated by:ย Boaz Barzel | Field CTO, @OX__Security ๐Ÿ“ox.security/vibeseccon-returโ€ฆ Tues - June 16, 2026 12PM ET | 9AM PT | 6PM CEST VibeSecCon: The Security Summit Running From Prompt to Runtime
1
4
60
OX Security retweeted
@AppSec_Village keeps growing! Welcome @OX__Security as our newest Bronze Sponsor ๐Ÿ’€ Check them out โฌ‡๏ธ ox.security/?utm_source=defcโ€ฆ #AppSecVillage #AppSec #ASPM #Shoutout #Sponsor
3
3
261
Agentic AI is rewriting the rules of security, introducing autonomous systems that can independently plan, act, and adapt across tools, environments, and workflows โ€” often in ways security teams can't fully predict. Who better to discuss the future of Agentic AI security than the leaders navigating it today? ๐Ÿง  Strategic Session Governing What You Can't Predict: A CISO's Framework for Agentic Risk โšก Moderated by: @chenxiwang | Managing General Partner, @rain_capital Featuring a panel of veteran CISOs: ๐Ÿ›ก๏ธย Daniel Liberย | CISO, @mondaydotcom ๐Ÿ›ก๏ธย Samir Sherifย | Global Field CISO, @fastly ๐Ÿ›ก๏ธย Pieter VanIperenย | CISO, @AlphaSenseInc ๐ŸŽŸ๏ธ ๐™๐™š๐™œ๐™ž๐™จ๐™ฉ๐™š๐™ง ๐™๐™ค๐™™๐™–๐™ฎ - ๐˜ฟ๐™ค๐™ฃ'๐™ฉ ๐™ˆ๐™ž๐™จ๐™จ ๐™Š๐™ช๐™ฉ! ox.security/vibeseccon-returโ€ฆ Tues - June 16, 2026 12PM ET | 9AM PT | 6PM CEST VibeSecCon: The Security Summit Running From Prompt to Runtime
5
124
๐Ÿšจ JUST ANNOUNCED ๐Ÿšจ VibeSecCon Returns on Tuesday - June 16th with: ๐Ÿš€ @begimher | Sr. Security Engineer, @awscloud โšก @JamesBerthotyย  | Founder & CEO, @latiotech ๐Ÿš€ @pmungse | Head of Security, @Poshmarkapp โšก @chenxiwang | Managing General Partner, @rain_capital ๐Ÿš€ @neatsun | CEO & Co-Founder, OX Security โšก @MosheTov | Security Research Team Leader ๐Ÿš€ and more rockstars from @OX__Security, @mondaydotcom, @fastly, @AlphaSenseInc ๐ŸŽŸ๏ธ REGISTER TODAY ๐Ÿ“ ox.security/vibeseccon-returโ€ฆ
2
5
151
๐Ÿšจ Breaking: Miasma Malware Goes Open Source (Hades / Shai-Hulud Variants) TeamPCP's decision to open-source Shai-Hulud has spawned even more copycats, giving threat actors more tools to spread supply chain malware online. Thanks to @KirkDerpca for bringing this to our attention!
24
89
8,311
๐Ÿšจ The future of security isn't AI vs humans... it's AI vs AI ๐ŸฅŠ Autonomous agents are already writing, fixing, and deploying code. The question isn't whether they'll make mistakes. It's whether security can keep up. ๐ŸŽฅ insights from our Field CTO, Boaz Barzel. #CyberSecurity #AIAgents #AppSec
3
173
OX Security researchers have analyzed and confirmed that the attack on the Azure GitHub repositories is part of the Miasma supply chain attack. Our analysis shows that the new infection repository string, "Hades - The End for the Damned," has replaced "Miasma - The Spreading Blight" and the prior "Shai-Hulud: Here We Go Again" strings. According to @ossmalware, a total of 73 repositories were compromised in the attack. We are currently investigating this attack, and more details will follow.
17
69
5,727
SPICY TAKE ๐ŸŒถ๏ธ๐Ÿ”ฅ who gets replaced first by AI? ๐Ÿ‘€ You? Your boss? Or both? Who's more exposed to AI disruption over the next 5 years? #AI #CyberSecurity #FutureOfWork #Leadership
1
4
233
๐Ÿšจ WAVE #3: the Miasma Shai-Hulud campaign infecting even more packages. Another wave of new malicious npm packages have been identified, adding to a growing list of compromised dependencies affecting the open source ecosystem. github-archiver@1.5.6 @ethlete/query@5.43.2 @ethlete/dsp@0.3.1 @ethlete/cdk@4.71.2 @ethlete/theming@2.7.1 @ethlete/cli@2.0.1 @ethlete/contentful@3.9.1 @ethlete/types@1.11.4 @ethlete/core@4.31.1 @ethlete/components@3.3.1 @forjacms/analytics@1.8.5 @forjacms/client@1.8.5 @forjacms/sections@1.8.5 @forjacms/sections-react@1.8.5 We are actively tracking the infections as they unfold and updating our research blog with the latest information. You can read more details here: โฌ‡๏ธ ox.security/blog/600000-montโ€ฆ
3
7
3,999
๐Ÿšจ BREAKING: the Miasma Shai-Hulud campaign is still spreading. New malicious npm packages have been identified, adding to a growing list of compromised dependencies affecting the open source ecosystem. We are actively tracking the infections as they unfold and updating our research with the latest indicators, affected packages, and attack activity. weโ€™ve we updated the list of malicious packages on our blog โฌ‡๏ธ ox.security/blog/600000-montโ€ฆ
2
9
7,376
๐Ÿ”ฅ Three categories. One OX. Proud to be recognized as a Sample Vendor in the Gartnerยฎ Hype Cycleโ„ข for Secure Software Engineering, 2026 for: โšก Agentic Coding Security โšก ASPM โšก Software Supply Chain Security we're just getting started ๐Ÿš€ FULL BLOG ox.security/blog/ox-securityโ€ฆ
3
148
have you registered yet? โฌ‡๏ธ VibeSecCon returns with three sessions on whatโ€™s keeping security teams up right now: faster exploitation, higher CVE volumes, and what happens when both attackers and defenders run on agents. ๐Ÿ”— ox.security/vibeseccon-returโ€ฆ ๐Ÿ“… Tuesday - June 16, 2026 โฐ 12:00 PM ET | 9:00 AM PT | 6:00 PM CEST ๐ŸŽฏ VibeSecCon Returns: The Security Summit Running From Prompt to Runtime ๐™๐™š๐™–๐™ฉ๐™ช๐™ง๐™ž๐™ฃ๐™œ ๐™ง๐™ค๐™˜๐™ ๐™จ๐™ฉ๐™–๐™ง ๐™จ๐™ฅ๐™š๐™–๐™ ๐™š๐™ง๐™จ: ๐Ÿ”ธ @MosheTov | Security Research Team Leader, @OX__Security ๐Ÿ”ธ @JamesBerthotyย  | Founder & CEO, @latiotech ๐Ÿ”ธ @chenxiwang | Managing General Partner, @rain_capital ๐Ÿ”ธ @begimher | Sr. Security Engineer, @awscloud ... full speaker lineup drops next week ๐Ÿค˜
1
13
693
๐Ÿšจ Miasma Returns: 600K Downloads at Risk 57 npm packages compromised ~647K monthly downloads ๐ŸŽฏ Executes via binding.gyp ๐Ÿ’ฅ Steals GitHub, npm & cloud creds ๐Ÿ›ก๏ธ Rotate keys, enable 2FA, assume compromise FULL REPORT: ox.security/blog/600000-montโ€ฆ #CyberSecurity #SupplyChainSecurity #AppSec
3
9
556