IQ AI / autonomous offensive security

Baghdad, Iraq / 33.3152 N  44.3661 E

Built in Iraq. Proven in public.

Find the path.Prove the exploit.

Autonomous agents map attack surfaces, reason through non-obvious paths, and return reproducible evidence instead of scanner noise.

Inspect verified research
Public CVEs
02
Research references
07
Validation standard
Proof

Operation trace / authorized scope

RUNNING
  1. 01InputScope & target intake
  2. 02Recon AgentSurface mapping
  3. 03Reasoning AgentAttack-path logic
  4. 04Validation AgentReproducible proof
  5. 05Report AgentStructured disclosure

07

Research that left a public record.

Authorized bug bounty and disclosure work involving globally recognized products. The claims here point to public outcomes, not vague promises.

  • APNIC
  • MyFitnessPal

Company names and logos reference public security research outcomes. They do not imply partnership, sponsorship, or endorsement.

Public case files / 2026

Two disclosures. Every reference included.

Confirmed findings move through coordinated disclosure before they appear here. Each record links back to the public source.

  1. CVE-2026-34912

    Responsibly disclosed

    Revive Adserver

    Missing access control check

    IQ AI identified an access-control weakness affecting Revive Adserver, where low-privileged users could create inconsistent ownership relationships when linking banners or campaigns to zones.

    Severity
    Medium
    References
    02
  2. CVE-2026-34913

    Responsibly disclosed

    Revive Adserver

    Missing access control check

    IQ AI identified an access-control weakness affecting Revive Adserver, where low-privileged users could link trackers to campaigns owned by other managers on the same instance.

    Severity
    Medium
    References
    02

From scope to disclosure, every pass has a job.

Specialized agents build on the same investigation. Human review stays in the loop where judgment, safety, and reporting quality matter.

  1. AI Recon

    IQ AI maps targets, discovers assets, understands application behavior, and builds a security-focused model of the attack surface.

  2. Vulnerability Reasoning

    AI agents reason through business logic, access control, authentication flows, API behavior, and chained attack paths.

  3. Exploit Validation

    IQ AI focuses on reproducible proof, reducing noise and prioritizing findings that can be clearly demonstrated and responsibly reported.

  4. Report Generation

    Findings are transformed into structured reports with impact, reproduction steps, affected components, and remediation guidance.

Adaptive model routing

Frontier reasoning, routed by the job.

IQ AI assigns each stage to the model best suited to the task, then verifies the result through the same evidence pipeline.
OpenAI

GPT 5.6

Deep attack-path reasoning and exploit development.

Anthropic

Fable 5

Long-context analysis, validation, and report synthesis.

An alert only matters when someone else can reproduce it.

Validated Impact
Every finding is anchored to a concrete, demonstrable security impact, not a theoretical possibility.
Clear Reproduction
Reproduction steps are precise and self-contained, so security teams can confirm an issue in minutes.
Responsible Disclosure
Research follows authorized programs and coordinated disclosure, prioritizing safety for users and vendors.

Authorized research starts with a clear scope and ends with a useful report.

Bring the target. We will bring the evidence.