ZeroHour
Vendor

OX Security

1 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Cybersecurity jobs available right now: August 4, 2026

Help Net Security lists cybersecurity vacancies at NATO DIANA, Docusign, OX Security, Boston Scientific and other organizations across nine countries.

A routine job-board roundup listing cybersecurity vacancies including Application Security Engineer at Arcadia, Cybersecurity Lead at NATO DIANA, Lead Security Engineer at Docusign, Security Researcher at OX Security, and Senior Cybersecurity Engineer at Boston Scientific. Roles cover AppSec, GRC, IAM, cloud security, and medical device security across the USA, UK, New Zealand, India, Israel, and Greece. No security incident, vulnerability, or product news is involved.

Help Net Securityupdated · 1d agofirst · 6d agoOther 6 sources1

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

77 malicious 'evil twin' Open VSX extensions impersonated developer tools and exfiltrated hostnames and detailed workspace reconnaissance to mangorbit.com.

Manifold Security found 77 extensions uploaded to the Open VSX marketplace between July 26 and August 1, 2026 that impersonate real Microsoft VS Code Marketplace tools, with all 77 sending data to mangorbit.com. 58 lightweight variants exfiltrate the hostname, while 19 recon variants collect editor details, OS username, Git remote hosts, CI environment variables (GitHub, GitLab, Azure DevOps, Buildkite, CircleCI, Codespaces, Gitpod), and installed extension IDs. The recon variant retries for up to seven days and can fall back to a DNS TXT record for exfiltration if the primary domain is blocked. The extensions were removed from Open VSX by August 3, 2026; the disclosure follows a separate npm supply chain campaign, ChainDrop, which compromised 450 packages with a Shai-Hulud worm variant.

The Hacker News · 14d agoMalware

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

OX Security researchers found 24 npm packages abusing unpkg mirrors to host fake Cloudflare CAPTCHA pages that redirect victims to attacker-controlled phishing infrastructure.

OX Security researchers documented 24 npm packages whose single HTML pages, once mirrored on services like unpkg.com, render as fake Cloudflare CAPTCHA pages on trusted domains and redirect victims to attacker-controlled phishing infrastructure for ClickFix attacks or credential harvesting. An earlier version contacted a typosquat Microsoft login domain (login.microsofte.live); after Chrome Safe Browsing blocklisting, the actor switched to the KeyVal key-value store as a dead drop resolver, currently redirecting to the legitimate ChatGPT site. The approach mirrors Socket's October 2025 report on 175 npm packages abusing unpkg.com in the Beamglea campaign.

The Hacker News · 20d agoPhishing & fraud in the wild