// WE PUBLISH WHAT WE LEARN

Security Research & Analysis

Original computation on public data. Experiments with reproducible setups. Novel findings when we earn them. Every piece is labeled for exactly what it is.

//
AnalysisAUG 6, 2026

Continuous Verification vs Annual Pentest: 2026 Guide

Continuous verification vs annual penetration testing in 2026: how they differ, why the once-a-year model misses 67% of exploited vulns, and how to run both.

NexusVoid AI Research · 8 MIN READ
// TRENDING
// 07 ENTRIES
AnalysisAUG 6, 2026

AI Agent Security in 2026: LLM Vulnerabilities and Defenses

AI agent security in 2026: prompt injection, sandbox escapes, agent hijacking, and how to defend LLM agents with least privilege and continuous verification.

NexusVoid AI Research8 MIN READ
AnalysisAUG 4, 2026

Vulnerability Prioritization 2026: What CVSS Misses

Vulnerability prioritization in 2026: what CVSS misses, and how EPSS, CISA KEV, and exploit evidence fix it. A reference model with real CVE examples.

NexusVoid AI Research11 MIN READ
AnalysisJUL 9, 2026

Why AI-Built Apps Need a Different Pentest

AI writes code faster than anyone secures it, and the failure modes are new. Prompt injection, over-permissioned agents, secrets in generated code, and attacks on the AI assistant itself sit outside a standard pentest. Here is what testing an AI-built app should actually cover.

NexusVoid AI Research7 MIN READ
AnalysisJUL 9, 2026

Does SOC 2, ISO 27001, or PCI DSS Require a Penetration Test?

PCI DSS explicitly requires penetration testing; SOC 2, ISO 27001, and HIPAA do not name it but expect it in practice. A framework-by-framework answer on where a pentest is mandatory versus strongly expected.

NexusVoid AI Research6 MIN READ
AnalysisJUL 3, 2026

Does AI Actually Make SOC 2 Faster? We Fact-Checked the Compliance Vendors

Every compliance automation vendor claims AI makes SOC 2 dramatically faster - "50% less work", "80-90% faster evidence collection", "weeks instead of months". We compiled the quantified claims from the top-ranking pages and checked which ones disclose any methodology. Most don't. Here is what is actually substantiated, and the one thing about SOC 2 timelines that no AI can compress.

NexusVoid AI Research6 MIN READ
AnalysisJUL 3, 2026

Securing AI-Generated Code: What 23 Studies and 48,185 CVEs Actually Show

We reviewed 23 studies and industry datasets on AI-generated code security. Roughly one in three AI-generated code samples contains a vulnerability - a rate that has not improved across model generations - while CVE publications grew 139% in the four years AI went from writing none of our code to roughly a third of it. Here is what the evidence says actually works.

NexusVoid AI Research8 MIN READ
AnalysisJUL 2, 2026

Annual Pentests Would Have Missed 67% of 2025's Actively Exploited Vulnerabilities

We computed the disclosure-to-exploitation window for all 245 vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog in 2025. The median window is 26 days. Under an annual pentest schedule, an expected 67.5% would never be tested before exploitation - and quarterly testing still misses 54%.

NexusVoid AI Research6 MIN READ