Xploitix Logo
  • Home
  • About
  • Services
  • Blog
  • X-Pent
  • Contact Us
Research

Security Research & Insights

Deep-dives into offensive security, AI-powered pentesting, and real-world vulnerability research from the Xploitix team.

14 Articles
5 Categories
57 Min Read
Featured
AI Security

Agentic AI Is Powerful. But Who's Pentesting the Agents?

The vulnerability wasn't the AI itself. It was the lack of boundaries between data and instructions. As AI agents get integrated into CI/CD pipelines, customer support, and even security operations, the attack surface isn't shrinking. It's shape-shifting.

Xploitix
Xploitix Team March 14, 2026
4 min read
AI Security
4 min

AI Just Drove a 600-Firewall Campaign in 5 Weeks. Your SOC Was Built for Humans.

AWS disclosed an AI-orchestrated campaign that compromised 600+ FortiGate firewalls across 55 countries in five weeks. Anthropic separately disclosed GTG-1002, a Chinese state-sponsored operation where AI executed 80–90% of the attack. Two attributed disclosures, one inescapable pattern: AI is now driving attacks, not just advising them.

Xploitix
Xploitix Team Apr 22, 2026
Case Study
5 min

The Vercel Breach: How a Third-Party AI Tool Cost a Whole Platform

Vercel was breached through Context AI, a third-party tool used by a single employee. Attackers pivoted via Google Workspace, decrypted environment variables, and listed the database for sale on BreachForums for $2M. Every AI dependency is now part of your perimeter.

Xploitix
Xploitix Team Apr 19, 2026
CVE Analysis
4 min

CVE-2026-39987: Marimo Pre-Auth RCE Exploited in 10 Hours

Marimo, the popular reactive Python notebook, was hit with a critical pre-auth RCE (CVSS 9.3). An unauthenticated WebSocket endpoint exposed a full PTY shell. Working exploits appeared within 10 hours of disclosure. If you run Marimo, patch now.

Xploitix
Xploitix Team Apr 8, 2026
Compliance
6 min

Indian Startups: DPDP Act Is NOT a Future Problem Anymore

The DPDP Act isn't a future checkbox. It's a live regulatory requirement. Updated April 6: IRDAI now mandates DPDP-aligned controls, bi-annual grey/white-box pentests, and CERT-In empanelled audits for insurers. Compliance without security is false confidence.

Xploitix
Xploitix Team Mar 31, 2026 · Updated Apr 6
Case Study
5 min

Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer

Two malicious versions of litellm (3M+ daily downloads) were published to PyPI with a three-stage payload: credential harvesting, cloud key exfiltration, and persistent remote access. If you use litellm, read this now.

Xploitix
Xploitix Team Mar 26, 2026
Vulnerability Research
3 min

How AI Caught a Business Logic Flaw That Scanners Missed

No complex payloads. No sophisticated exploits. Just a simple validation mistake that could have cost ~100K credits. Our AI platform detected a credit-based API flaw where negative values increased the user balance instead of decreasing it.

Xploitix
Xploitix Team Mar 13, 2026
Vulnerability Research
4 min

Broken Access Control: When Encrypted IDs Aren't Enough

This type of vulnerability usually requires manual testing, because it depends on application logic rather than payload injection. Our AI system identified cross-role authorization vulnerabilities where encrypted identifiers from privileged users could be reused by lower-privilege users.

Xploitix
Xploitix Team Mar 11, 2026
Case Study
5 min

3 Engineers. 1 AI Prompt. $62 Million in Risk Exposure.

Samsung engineers exposed semiconductor source code to ChatGPT. This isn't a hypothetical scenario. It's a case study in how LLM adoption without security guardrails creates enterprise-scale risk.

Xploitix
Xploitix Team Mar 11, 2026
Vulnerability Research
3 min

Your Perimeter Is No Longer Enough

Attackers aren't brute-forcing your firewall anymore. They're targeting identity, APIs, and supply chains. The traditional perimeter-based security model was built for a world that no longer exists.

Xploitix
Xploitix Team Mar 10, 2026
AI Pentesting
4 min

AI-Powered Pentesting Is No Longer a Concept. It's Operational.

Security is not about the number of alerts generated. It is about the credibility of findings under scrutiny. Our AI platform produced validated findings with CVSS scores ranging from 5.3 to 7.5, triaged for real-world impact.

Xploitix
Xploitix Team Feb 18, 2026
CVE Analysis
5 min

CVE-2026-21992: Oracle Identity Manager RCE (CVSS 9.8)

Oracle issued an emergency out-of-band patch for a critical unauthenticated RCE in Identity Manager and Web Services Manager. CVSS 9.8. No user interaction required. If you run Oracle Fusion Middleware, patch now.

Xploitix
Xploitix Team Mar 21, 2026
CVE Analysis
4 min

CVE-2026-33017: Langflow RCE Exploited Within 20 Hours

A critical authentication bypass and code injection flaw in the popular AI platform Langflow saw active exploitation within 20 hours of disclosure. CVSS 9.3. If you build AI pipelines, read this now.

Xploitix
Xploitix Team Mar 19, 2026
CVE Analysis
3 min

CVE-2026-32746: Telnetd Root RCE Threatens ICS/OT Systems

A critical unpatched flaw in GNU InetUtils telnetd allows unauthenticated root-level code execution. CVSS 9.8. Industrial control systems and legacy infrastructure are the primary targets.

Xploitix
Xploitix Team Mar 15, 2026

Want to Stay Ahead of Threats?

Follow us on LinkedIn for daily security insights, or get in touch for a free consultation.

Follow on LinkedIn Get in Touch

Xploitix
Xploitix Team
Xploitix Logo

Your Attack Surface, Our Battlefield

Quick Links

  • Home
  • About
  • Services
  • Blog
  • X-Pent
  • Contact Us

Get in Touch

contact@xploitix.in

+91 8688443191

Hyderabad, India

© 2025 Xploitix Technologies LLP. All rights reserved. | Terms · Privacy · Refund Policy