Official company update
Four Critical CVEs, the Same Trust Issue
OX Security·ox.security·
What the source says
Last week, 4 unauthenticated critical CVEs turned up in 24 hours, all sharing the same mistake: a component trusting the layer next to it Read our technical analysis of these 4 critical CVEs Within a single 24-hour window last week, four critical vulnerabilities landed across widely deployed infrastructure: two in Next.js, one in Netty, one […] The pos
Checking access…
The original publication, including any images and updates, remains with the publisher.
Checking free source access…
More about OX Security
Official · ox.security“Shai-Hulud: Here We Go Again” – “tensorlake” npm Package Hit With MalwareOfficial · ox.securitySSRF in Harbor Webhooks: Any User Can Reach the Server’s Cloud CredentialsOfficial · ox.securityCVE-2026-93355: Account Takeover in LiteLLMOfficial · ox.securityPhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels