Alastor InfoSec

Blog

Research, Guides & Security Notes

Compliance checklists, vulnerability research, and field notes from continuous VAPT and AI agent security engagements — search or filter to find what's relevant to you.

78 Articles

VAPTAugust 17, 2026

PTaaS vs Annual Penetration Testing in 2026: Why Continuous Testing Is No Longer Optional for Indian Businesses

The penetration testing market hits $2.72B in 2026 — why annual VAPT leaves 80% of your attack surface untested and how PTaaS closes the gap for Indian businesses under DPDPA.

VAPTPenetration TestingPTaaS
ComplianceAugust 17, 2026

DPDPA November 2026 Consent Manager Deadline Is 13 Weeks Away: What Indian Businesses Must Do Right Now

India's DPDP Act Phase 2 Consent Manager deadline is November 13, 2026 — the five critical compliance steps every Indian Data Fiduciary must complete in the next 13 weeks.

DPDPAComplianceConsent Manager
VulnerabilityAugust 17, 2026

CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE (CVSS 9.8) Added to CISA KEV — Patch to 7.2.63.2 Now

Unauthenticated command injection in Progress Kemp LoadMaster is actively exploited — 792 attempts from 65 IPs in 41 days. Patch to GA 7.2.63.2 or LTSF 7.2.54.18 immediately.

CVE-2026-8037Progress Kemp LoadMasterCISA KEV
ComplianceAugust 7, 2026

DPDPA Significant Data Fiduciaries 2026: MeitY's 12-Month Proposal and What Indian Tech Firms Must Do Now

MeitY is consulting on shortening the SDF compliance window from 18 to 12 months — here's what Significant Data Fiduciaries must implement before the deadline closes in.

DPDPAComplianceSignificant Data Fiduciary
VulnerabilityAugust 7, 2026

CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass (CVSS 7.5) Added to CISA KEV — Patch to 11.0.21 Now

Apache Tomcat's cluster encryption interceptor can be bypassed in three specific builds, exposing organisations to potential unauthenticated RCE — CISA added CVE-2026-34486 to KEV on August 4, 2026.

CVE-2026-34486Apache TomcatCISA KEV
VAPTAugust 7, 2026

AI-Enabled Autonomous Hacking in 2026: Why Human-Only Red Teams Can't Keep Up Anymore

AI agent frameworks are now driving offensive campaigns against real infrastructure — what agentic red teaming means for VAPT programmes and how Indian enterprises need to respond in 2026.

VAPTPenetration TestingAgentic Red Teaming

We use cookies to keep the platform secure and understand how our site is used. See our Security & Data policy for details.