Resources

Threat intelligence, case studies, and security research from the Intruex team.

Featured Article

A man in Melbourne asked his personal AI agent to move him up a gym waitlist. It found two API flaws and cancelled a stranger’s reservation. The vulnerabilities were entirely ordinary — what is new is who found them, and why your triage model assumes an attacker who no longer has to exist.

2
API Flaws Found by an Agent Asked to Book a Class
#1
Broken Object Level Auth’s Rank on the OWASP API Top 10
0
Malware, Exploit Code, or Attacker Infrastructure Involved
1
Real Reservation Cancelled by Something With No Intent

Nobody Asked It to Hack Anything: An AI Agent, a Gym Booking API, and the End of Intent-Based Triage

Neither flaw was clever. Broken Object Level Authorization has topped the OWASP API list since it existed. The gym’s booking system was never protected by being hard to break — it was protected by nobody capable ever having a reason to look. That protection ended this month. From the gym’s logs, the whole incident is a real member, a real session, and well-formed requests returning 200.

Aug 2026 · 9 min read Read Article
Article

Your Escrow Account Is the Target: Wire Fraud and ALTA Pillar 3

BEC losses hit $3.04 billion in 2025, and home closings remain a favorite target. The diverted wire is the last step of the attack — and every stage before it sits in logs your agency already generates.

Aug 2026 · 9 min read Read Article
Article

Reg S-P Is Now Fully in Force: Why “We Have a Compliance Consultant” No Longer Covers Your RIA

As of June 3, 2026, the SEC’s amended Regulation S-P applies to every RIA. An incident response program and 30-day customer notification are mandatory — and the word that breaks the consultant model is “detect.”

Aug 2026 · 9 min read Read Article
Article

The CMMC Pause Didn’t Pause Your Obligations

CMMC Phase 2 is suspended pending a reform review due mid-September 2026, but DFARS 252.204-7012, SPRS self-assessments, and NIST SP 800-171 remain fully in force. The suspension removed the auditor — and concentrated your exposure.

Aug 2026 · 10 min read Read Article
Article

The HIPAA Requirement Nobody at a Small Practice Actually Performs

45 CFR §164.308(a)(1)(ii)(D) requires regular review of system activity logs — required, not addressable, and in force for twenty years. At practices holding the most sensitive PHI in medicine, nobody has ever done it.

Aug 2026 · 9 min read Read Article
Article

Signed, Verified, Poisoned: The npm Worm That Weaponized Developer AI Agents

The August 4 keyv compromise poisoned 444 npm packages in three hours and forty-three minutes and harvested credentials from GitHub Actions runner memory. Every poisoned release carried valid provenance — and payloads fired on folder open, no install required.

Aug 2026 · 10 min read Read Article
Article

14 Mega-Breaches, Three Playbooks: How ShinyHunters Dominated H1 2026

ShinyHunters is linked to 14 of the 37 largest confirmed breaches of H1 2026 — Salesforce, Charter, Carnival, Telus Digital, the Council of Europe. Three playbooks, one common failure: alerts that were never investigated in time.

Jul 2026 · 9 min read Read Article
Article

The Front Door Was Open: A VPN Zero-Day and Qilin Ransomware

CVE-2026-50751 (CVSS 9.3) — a certificate validation flaw in Check Point Remote Access VPN gives unauthenticated attackers remote access. How Qilin ransomware exploited it, and why edge-device entry defeats traditional detection.

Jul 2026 · 9 min read Read Article
Article

When Exploits Arrive Before Patches: The AI-Enabled Attack Surge

AI-enabled adversary activity surged 89% year-over-year, and 28.3% of CVEs are exploited within 24 hours of disclosure. How AI is compressing attacker timelines beyond what human-speed investigation can match.

Jul 2026 · 9 min read Read Article
Article

Talking Through the Walls: DragonForce Teams C2

DragonForce built the first malware using Microsoft Teams TURN relay for command-and-control. Why the C2 channel passes network inspection — and why cross-telemetry correlation is the only way to catch it.

Jul 2026 · 8 min read Read Article
Article

Living in the Walls: Volt Typhoon and Salt Typhoon

Two Chinese state-sponsored campaigns with five-year dwell times inside US critical infrastructure and every major US telecom. The alerts fired — the investigation didn’t happen.

Apr 2026 · 12 min read Read Article
Article

The 2026 Ransomware Surge

Ransomware operators are shutting down trauma centers, paralyzing city governments, and disrupting medical device supply chains. An analysis of four early-2026 attacks and why traditional SOC models can’t contain them before detonation.

Apr 2026 · 10 min read Read Article
Article

SIEM vs SOAR vs XDR vs AI SOC

What each security operations technology actually does, where they overlap, and how to choose the right combination for your organization.

2026 · 12 min read Read Article
Article

How One Hacker Used AI to Breach an Entire Government

A single attacker used a $20/month AI subscription to breach 9 government agencies and exfiltrate 150GB of sensitive data. We break down every phase and show where AI-powered SOC detection would have intervened.

Feb 2026 · 12 min read Read Article
Article

How Attack Narrative Correlation Works

Learn how Intruex automatically correlates related security alerts into unified attack campaigns, maps them to MITRE ATT&CK kill chain phases, and generates analyst-ready narratives.

2025 · 8 min read Read Article
Article

The AI SOC Buyer's Guide

What to look for when evaluating AI-powered SOC platforms. Covers agent architecture, deployment flexibility, compliance mapping, and the difference between AI-assisted and AI-autonomous operations.

2025 · 10 min read Read Article
Article

Air-Gapped AI: Securing Classified Environments

How Intruex delivers the same AI-powered security operations in fully disconnected networks using self-hosted LLMs and local inference — no cloud dependency required.

2025 · 7 min read Read Article

See Intruex in Action

Want to see how AI-powered SOC operations detect threats that traditional tools miss? Let's talk.