Security Research & Insights

Deep-dives into offensive security, AI-powered pentesting, and real-world vulnerability research from the Xploitix team.

14 Articles
5 Categories
57 Min Read
Featured
AI Security
4 min

AI Just Drove a 600-Firewall Campaign in 5 Weeks. Your SOC Was Built for Humans.

AWS disclosed an AI-orchestrated campaign that compromised 600+ FortiGate firewalls across 55 countries in five weeks. Anthropic separately disclosed GTG-1002, a Chinese state-sponsored operation where AI executed 80–90% of the attack. Two attributed disclosures, one inescapable pattern: AI is now driving attacks, not just advising them.

Case Study
5 min

The Vercel Breach: How a Third-Party AI Tool Cost a Whole Platform

Vercel was breached through Context AI, a third-party tool used by a single employee. Attackers pivoted via Google Workspace, decrypted environment variables, and listed the database for sale on BreachForums for $2M. Every AI dependency is now part of your perimeter.

CVE Analysis
4 min

CVE-2026-39987: Marimo Pre-Auth RCE Exploited in 10 Hours

Marimo, the popular reactive Python notebook, was hit with a critical pre-auth RCE (CVSS 9.3). An unauthenticated WebSocket endpoint exposed a full PTY shell. Working exploits appeared within 10 hours of disclosure. If you run Marimo, patch now.

Compliance
6 min

Indian Startups: DPDP Act Is NOT a Future Problem Anymore

The DPDP Act isn't a future checkbox. It's a live regulatory requirement. Updated April 6: IRDAI now mandates DPDP-aligned controls, bi-annual grey/white-box pentests, and CERT-In empanelled audits for insurers. Compliance without security is false confidence.

Vulnerability Research
3 min

How AI Caught a Business Logic Flaw That Scanners Missed

No complex payloads. No sophisticated exploits. Just a simple validation mistake that could have cost ~100K credits. Our AI platform detected a credit-based API flaw where negative values increased the user balance instead of decreasing it.

Vulnerability Research
4 min

Broken Access Control: When Encrypted IDs Aren't Enough

This type of vulnerability usually requires manual testing, because it depends on application logic rather than payload injection. Our AI system identified cross-role authorization vulnerabilities where encrypted identifiers from privileged users could be reused by lower-privilege users.

Case Study
5 min

3 Engineers. 1 AI Prompt. $62 Million in Risk Exposure.

Samsung engineers exposed semiconductor source code to ChatGPT. This isn't a hypothetical scenario. It's a case study in how LLM adoption without security guardrails creates enterprise-scale risk.

Vulnerability Research
3 min

Your Perimeter Is No Longer Enough

Attackers aren't brute-forcing your firewall anymore. They're targeting identity, APIs, and supply chains. The traditional perimeter-based security model was built for a world that no longer exists.

AI Pentesting
4 min

AI-Powered Pentesting Is No Longer a Concept. It's Operational.

Security is not about the number of alerts generated. It is about the credibility of findings under scrutiny. Our AI platform produced validated findings with CVSS scores ranging from 5.3 to 7.5, triaged for real-world impact.

CVE Analysis
5 min

CVE-2026-21992: Oracle Identity Manager RCE (CVSS 9.8)

Oracle issued an emergency out-of-band patch for a critical unauthenticated RCE in Identity Manager and Web Services Manager. CVSS 9.8. No user interaction required. If you run Oracle Fusion Middleware, patch now.

CVE Analysis
4 min

CVE-2026-33017: Langflow RCE Exploited Within 20 Hours

A critical authentication bypass and code injection flaw in the popular AI platform Langflow saw active exploitation within 20 hours of disclosure. CVSS 9.3. If you build AI pipelines, read this now.

CVE Analysis
3 min

CVE-2026-32746: Telnetd Root RCE Threatens ICS/OT Systems

A critical unpatched flaw in GNU InetUtils telnetd allows unauthenticated root-level code execution. CVSS 9.8. Industrial control systems and legacy infrastructure are the primary targets.

Want to Stay Ahead of Threats?

Follow us on LinkedIn for daily security insights, or get in touch for a free consultation.