Blog
Research, Guides & Security Notes
Compliance checklists, vulnerability research, and field notes from continuous VAPT and AI agent security engagements — search or filter to find what's relevant to you.
78 Articles
PTaaS vs Annual Penetration Testing in 2026: Why Continuous Testing Is No Longer Optional for Indian Businesses
The penetration testing market hits $2.72B in 2026 — why annual VAPT leaves 80% of your attack surface untested and how PTaaS closes the gap for Indian businesses under DPDPA.
DPDPA November 2026 Consent Manager Deadline Is 13 Weeks Away: What Indian Businesses Must Do Right Now
India's DPDP Act Phase 2 Consent Manager deadline is November 13, 2026 — the five critical compliance steps every Indian Data Fiduciary must complete in the next 13 weeks.
CVE-2026-8037: Progress Kemp LoadMaster Pre-Auth RCE (CVSS 9.8) Added to CISA KEV — Patch to 7.2.63.2 Now
Unauthenticated command injection in Progress Kemp LoadMaster is actively exploited — 792 attempts from 65 IPs in 41 days. Patch to GA 7.2.63.2 or LTSF 7.2.54.18 immediately.
DPDPA Significant Data Fiduciaries 2026: MeitY's 12-Month Proposal and What Indian Tech Firms Must Do Now
MeitY is consulting on shortening the SDF compliance window from 18 to 12 months — here's what Significant Data Fiduciaries must implement before the deadline closes in.
CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass (CVSS 7.5) Added to CISA KEV — Patch to 11.0.21 Now
Apache Tomcat's cluster encryption interceptor can be bypassed in three specific builds, exposing organisations to potential unauthenticated RCE — CISA added CVE-2026-34486 to KEV on August 4, 2026.
AI-Enabled Autonomous Hacking in 2026: Why Human-Only Red Teams Can't Keep Up Anymore
AI agent frameworks are now driving offensive campaigns against real infrastructure — what agentic red teaming means for VAPT programmes and how Indian enterprises need to respond in 2026.