Threat intelligence, case studies, and security research from the Intruex team.
BEC losses hit $3.04 billion in 2025, and home closings remain a favorite target. The diverted wire is the last step of the attack — and every stage before it sits in logs your agency already generates.
As of June 3, 2026, the SEC’s amended Regulation S-P applies to every RIA. An incident response program and 30-day customer notification are mandatory — and the word that breaks the consultant model is “detect.”
CMMC Phase 2 is suspended pending a reform review due mid-September 2026, but DFARS 252.204-7012, SPRS self-assessments, and NIST SP 800-171 remain fully in force. The suspension removed the auditor — and concentrated your exposure.
45 CFR §164.308(a)(1)(ii)(D) requires regular review of system activity logs — required, not addressable, and in force for twenty years. At practices holding the most sensitive PHI in medicine, nobody has ever done it.
The August 4 keyv compromise poisoned 444 npm packages in three hours and forty-three minutes and harvested credentials from GitHub Actions runner memory. Every poisoned release carried valid provenance — and payloads fired on folder open, no install required.
ShinyHunters is linked to 14 of the 37 largest confirmed breaches of H1 2026 — Salesforce, Charter, Carnival, Telus Digital, the Council of Europe. Three playbooks, one common failure: alerts that were never investigated in time.
CVE-2026-50751 (CVSS 9.3) — a certificate validation flaw in Check Point Remote Access VPN gives unauthenticated attackers remote access. How Qilin ransomware exploited it, and why edge-device entry defeats traditional detection.
AI-enabled adversary activity surged 89% year-over-year, and 28.3% of CVEs are exploited within 24 hours of disclosure. How AI is compressing attacker timelines beyond what human-speed investigation can match.
DragonForce built the first malware using Microsoft Teams TURN relay for command-and-control. Why the C2 channel passes network inspection — and why cross-telemetry correlation is the only way to catch it.
Two Chinese state-sponsored campaigns with five-year dwell times inside US critical infrastructure and every major US telecom. The alerts fired — the investigation didn’t happen.
Ransomware operators are shutting down trauma centers, paralyzing city governments, and disrupting medical device supply chains. An analysis of four early-2026 attacks and why traditional SOC models can’t contain them before detonation.
What each security operations technology actually does, where they overlap, and how to choose the right combination for your organization.
A single attacker used a $20/month AI subscription to breach 9 government agencies and exfiltrate 150GB of sensitive data. We break down every phase and show where AI-powered SOC detection would have intervened.
Learn how Intruex automatically correlates related security alerts into unified attack campaigns, maps them to MITRE ATT&CK kill chain phases, and generates analyst-ready narratives.
What to look for when evaluating AI-powered SOC platforms. Covers agent architecture, deployment flexibility, compliance mapping, and the difference between AI-assisted and AI-autonomous operations.
How Intruex delivers the same AI-powered security operations in fully disconnected networks using self-hosted LLMs and local inference — no cloud dependency required.
Want to see how AI-powered SOC operations detect threats that traditional tools miss? Let's talk.