Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Resources

Resources

Analysis from the people building it

Analysis of AI SOC evaluation, alert triage, deployment sovereignty and the compliance verbs regulators actually use. Written by the people building the platform, which means it is opinionated and occasionally inconvenient for us.

Archive

Everything else

10 August 2026

Nobody Asked It to Hack Anything: An AI Agent, a Gym Booking API, and the End of Intent-Based Triage

A Melbourne man asked his personal AI agent to move him up a gym waitlist. It found two API flaws and canceled a stranger's reservation. The vulnerabilities were…

Read

9 August 2026

The HIPAA Requirement Nobody at a Small Practice Actually Performs: Information System Activity Review

HIPAA's Security Rule, 45 CFR ยง164.308(a)(1)(ii)(D), requires regular review of system activity logs. It is required, not addressable. For small behavioral health…

Read

9 August 2026

The CMMC Pause Didn't Pause Your Obligations: What NIST 800-171 Still Requires of Small Defense Subcontractors

CMMC Phase 2 is suspended pending a reform review due mid-September 2026, but DFARS 252.204-7012, SPRS self-assessments, and NIST SP 800-171 remain fully in force. With…

Read

9 August 2026

Reg S-P Is Now Fully in Force: Why "We Have a Compliance Consultant" No Longer Covers Your RIA

As of June 3, 2026, the SEC's amended Regulation S-P applies to every RIA, including smaller firms. A written incident response program and 30-day customer notification…

Read

9 August 2026

Your Escrow Account Is the Target: Wire Fraud, ALTA Pillar 3, and What Title Agencies Are Expected to Monitor

BEC losses hit $3.04 billion in 2025, and home closings are a favorite target. What ALTA Best Practices Pillar 3 and your underwriter actually expect a title agency's…

Read

5 August 2026

Signed, Verified, Poisoned: The npm Worm That Weaponized Developer AI Agents

On August 4, 2026, a self-propagating npm worm poisoned hundreds of packages in under four hours, and shipped hooks that execute the moment a developer opens the repo in…

Read

17 July 2026

14 Mega-Breaches, Three Playbooks: How ShinyHunters Dominated H1 2026

ShinyHunters is the top threat actor of H1 2026, linked to 14 of the largest confirmed breaches. Analysis of the three attack playbooks: voice phishing, cloud…

Read

14 July 2026

The Front Door Was Open: How a VPN Zero-Day Gave Qilin Ransomware Unauthenticated Access

CVE-2026-50751 (CVSS 9.3): a logic flaw in Check Point Remote Access VPN IKEv1 certificate validation gives unauthenticated attackers remote access. Analysis of the…

Read

11 July 2026

When Exploits Arrive Before Patches: The 24-Hour Window Defenders Are Losing

AI-enabled attacks surged 89% year-over-year per CrowdStrike's 2026 Global Threat Report, with 28.3% of CVEs exploited within 24 hours of disclosure. Analysis of how AI…

Read

11 July 2026

Talking Through the Walls: How DragonForce Ransomware Hides C2 Inside Microsoft Teams Infrastructure

DragonForce deploys the first malware using Microsoft Teams TURN relay for command-and-control. Analysis of how Backdoor.Turn exploits trusted infrastructure to make C2…

Read

16 April 2026

Living in the Walls: Why Volt Typhoon and Salt Typhoon Dwell in Critical Infrastructure for Years

Chinese state-sponsored APTs Volt Typhoon and Salt Typhoon have spent up to five years inside US critical infrastructure and every major US telecom. An analysis of why…

Read

6 April 2026

The 2026 Ransomware Surge: Why Hospitals, Cities, and Critical Infrastructure Can't Respond Fast Enough

Ransomware attacks are shutting down trauma centers, paralyzing city governments, and disrupting medical supply chains. An analysis of the 2026 ransomware surge and why…

Read

30 March 2026

SIEM vs SOAR vs XDR vs AI SOC: What's the Difference?

A vendor-neutral comparison of SIEM, SOAR, XDR, and AI SOC platforms. Understand what each security operations technology does, where they overlap, and how to choose the…

Read

25 March 2025

How One Hacker Used AI to Breach an Entire Government

A single hacker used a consumer AI chatbot to breach 9 Mexican government agencies and steal 150GB of sensitive data, including 195 million taxpayer records. Here's what…

Read

25 March 2025

The AI SOC Buyer's Guide

A comprehensive buyer's guide for evaluating AI-powered SOC platforms. Covers agent architecture, alert processing depth, deployment models, compliance, SOAR…

Read

25 March 2025

Air-Gapped AI: Securing Classified Environments

How Intruex delivers the same AI-powered security operations in fully disconnected, air-gapped networks using self-hosted LLMs and local inference, no cloud dependency…

Read

25 March 2025

How Attack Narrative Correlation Works

SOC teams receive thousands of alerts daily, but isolated alerts don't tell a story. Learn how attack narrative correlation transforms fragmented signals into complete…

Read

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.