Blog

Insights from the offensive AI team

Engineering notes, research, customer stories, and the occasional rant from the team building autonomous pentesting at Intrudify.

Supply Chain

arrayref: 86 Minutes of Compromise

At 07:15 UTC on August 20, 2026, arrayref 0.3.10 appeared on crates.io, and within about 23 minutes, poisoned releases of internment 0.8.7 and append-only-vec 0.1.9 appeared. From the outside, everything looked like regular point releases of trusted packages.

August 21, 2026
Tudor LasuscheviciSecurity Researcher
Compliance

How to Prepare for a Security Audit

Audit preparation fails in the same two places every time, and neither is the audit itself. Here is the order of work, and the evidence list to build against.

August 19, 2026
Petru KovaciCTO
Compliance

SOC 2 vs ISO 27001: Which One Do You Actually Need?

They are not competing versions of the same thing. One is an audit report about your controls; the other is a certificate saying you run a management system. That difference decides which your buyer will accept.

August 19, 2026
Tudor LasuscheviciSecurity Researcher
Compliance

Compliance vs Security: Why Passing an Audit Is Not Being Safe

Every breached company with a clean audit report is the same story. Compliance measures whether you can demonstrate conformance; security measures whether an attacker gets in. Those come apart more often than anyone likes.

August 18, 2026
Radu NegriceaSecurity Researcher
Compliance

Risk Assessment for Compliance: How to Do One Auditors Accept

Most first risk assessments are a spreadsheet of generic threats with invented numbers. Auditors can tell. Here is the method that survives being asked "why this rating".

August 17, 2026
Petru KovaciCTO
Compliance

The NIST Cybersecurity Framework Explained

The CSF gets confused with every other NIST document, and with certification schemes it has nothing to do with. It is a voluntary structure for organising a security programme, and that is genuinely useful once you stop expecting a checklist.

August 14, 2026
Tudor LasuscheviciSecurity Researcher
Pricing

How Much Does a Penetration Test Cost?

Every honest answer to this starts with "it depends", so here is what it depends ON: the five factors that move the number, and the pricing models that hide it.

August 13, 2026
Petru KovaciCTO
Penetration Testing

SaaS Penetration Testing: Why Multi-Tenancy Changes Everything

For a SaaS product, the highest-severity finding is almost always the same shape: one customer reaching another customer's data. That is not a generic web app test.

August 12, 2026
Tudor LasuscheviciSecurity Researcher
Startup Security

The Startup Cybersecurity Checklist That Actually Matters

Most startup security checklists have two hundred items and no order, which makes them unusable. This one is ordered by what reduces the most risk per hour spent.

August 11, 2026
Petru KovaciCTO
Startup Security

When Does a Startup Actually Need a Penetration Test?

Not at incorporation, and not at Series B. The trigger is not company stage at all, which is why stage-based advice on this question is consistently unhelpful.

August 10, 2026
Radu NegriceaSecurity Researcher
Vulnerability Management

How to Reduce False Positives in Security Testing

Every team tries to fix this with tuning and suppression rules. Those help at the margins. The real cause is tools that report what might be true instead of what they confirmed.

August 7, 2026
Tudor LasuscheviciSecurity Researcher
Vulnerability Management

Vulnerability Prioritization: CVSS, EPSS and What Actually Matters

Sorting by CVSS score is the default and it is a poor strategy. Severity is not likelihood, and neither one knows anything about your application.

August 6, 2026
Radu NegriceaSecurity Researcher
Vulnerability Management

Vulnerability Scanning vs Penetration Testing: The Real Difference

These get sold as near-equivalents at very different prices. They are not close. One produces a list of things to check; the other produces a list of things that happened.

August 3, 2026
Tudor LasuscheviciSecurity Researcher
Penetration Testing

The Penetration Testing Process, Step by Step

Most descriptions of the pentest process are written for testers. This one is written for the person who has to schedule it, approve it, and explain the report to an engineering team.

July 31, 2026
Radu NegriceaSecurity Researcher
Penetration Testing

Types of Penetration Testing: Black Box, Grey Box, White Box

Two different things get called "types of penetration testing": how much the tester knows, and what they are pointed at. Mixing them up is how scopes end up wrong.

July 29, 2026
Petru KovaciCTO
Penetration Testing

Penetration Testing Methodology: PTES, OWASP and the Rest

A pentest without a named methodology is a tester following their instincts. The instincts might be excellent, but you cannot audit them, compare them, or tell what was skipped.

July 27, 2026
Tudor LasuscheviciSecurity Researcher
Penetration Testing

What Is Penetration Testing?

A plain explanation of what a penetration test is, what separates it from a vulnerability scan, who needs one, and what the report should actually give you.

July 24, 2026
Petru KovaciCTO
AI Security

Automated vs Continuous Security Testing: What Actually Differs

These two get used interchangeably, and they are not the same thing. One describes who performs the test, the other describes what triggers it. You can have either without the other, and most teams do.

July 22, 2026
Radu NegriceaSecurity Researcher
AI Security

AI vs Traditional Security Testing: Where Each One Wins

The useful comparison is not "which is better" but which constraint each one removes. Traditional testing is limited by human hours. AI-driven testing is limited by judgment. Those are different problems.

July 20, 2026
Tudor LasuscheviciSecurity Researcher
AI Security

The Benefits of AI in Cybersecurity, and Its Real Limits

Most writing on this topic is either a sales pitch or a warning. The useful version is a ledger: what AI actually improves, what it makes worse, and where the honest boundary sits.

July 17, 2026
Radu NegriceaSecurity Researcher
AI Security

How AI Is Used in Cybersecurity: A Practical Guide

AI in security is not one thing. It shows up in at least five distinct places, doing different jobs with different track records. Here is the map, with an honest note on which parts are mature.

July 16, 2026
Petru KovaciCTO
Security Research

Benchmarking Intrudify against two top-tier AI pentesters

Two commercial AI pentesters had already been run over Fider and Photoview. We pointed Intrudify at the same targets, attacked them by hand, and compared what each engine actually catches.

July 5, 2026
Tudor LasuscheviciSecurity Researcher
AI Security

Use Claude Fable 5 to Write Safer Code, Then Test Your Live App

Fable 5 genuinely raises your security baseline - but everything it does, it does by reading code. Why the running application is the half it can't reach, and how to cover the gap with dynamic testing.

June 11, 2026
Radu NegriceaSecurity Researcher
Security Culture

Beyond the Checklist: Building a Security-First Culture in Your Startup

All the security software in the world can't protect you from the biggest vulnerability of all: your people. A single click on a phishing email, a reused password, or a moment of carelessness can undo all your hard work.

September 5, 2025
Petru KovaciCTO
AI Security

A Founder's Guide to Using AI Securely: How to Move Fast Without Breaking Things

This isn't about telling you not to use AI - the opportunity cost of ignoring it is far too high. This is a pragmatic guide on how to use AI efficiently and securely, balancing the immense potential with smart, cost-effective risk management.

September 1, 2025
Marc Balasescu
Marc BalasescuCEO & Founder