Alastor InfoSec

Blog

Research, Guides & Security Notes

Compliance checklists, vulnerability research, and field notes from continuous VAPT and AI agent security engagements — search or filter to find what's relevant to you.

45 Articles

VAPTJuly 22, 2026

Red Team vs. Penetration Testing in 2026: When You Need Each One and What the Difference Actually Costs

Red teaming and penetration testing solve different problems — here's when to use each, what each engagement actually delivers, and why most Indian enterprises are running the wrong one.

VAPTPenetration TestingRed Team
VulnerabilityJuly 22, 2026

Fortinet FortiSandbox OS Command Injection: CVE-2026-25089 & CVE-2026-39808 (CVSS 9.1) Actively Exploited — Patch Now

Two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox are actively exploited for RCE — CISA added both to KEV July 16, patch to 4.4.9 or 5.0.6 immediately.

CVE-2026-25089CVE-2026-39808Fortinet FortiSandbox
ComplianceJuly 22, 2026

DPDPA Vendor Risk Management 2026: What Every Data Fiduciary Must Know About Third-Party Processors

India's DPDP Act places binding obligations on data fiduciaries for every vendor they share personal data with — here's the compliance framework before November 2026 enforcement.

DPDPAComplianceVendor Risk
VulnerabilityJuly 21, 2026

Joomla Extensions Under Active Attack: CVE-2026-48908, CVE-2026-48939, CVE-2026-56291 Added to CISA KEV (CVSS 10.0)

Three Joomla extension vulnerabilities with CVSS 10.0 scores are being actively exploited for unauthenticated file upload and RCE — patch now or take systems offline.

CVE-2026-48908CVE-2026-48939CVE-2026-56291
ComplianceJuly 21, 2026

DPDPA Data Localisation and Cross-Border Transfer Rules 2026: What Indian Businesses Must Know

India's DPDP Act imposes strict conditions on cross-border data transfers and data localisation — here's what every Indian business must do before November 2026 enforcement.

DPDPAComplianceData Localisation
VAPTJuly 21, 2026

Dark Web Monitoring in 2026: How 16 Billion Leaked Credentials Fuel Attacks on Indian Businesses

With 16 billion credentials circulating on dark web markets and the average employee leak window under 48 hours, dark web monitoring has become a core component of any serious VAPT programme.

VAPTDark Web MonitoringCredential Leak

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.