Blog
Research, Guides & Security Notes
Compliance checklists, vulnerability research, and field notes from continuous VAPT and AI agent security engagements — search or filter to find what's relevant to you.
45 Articles
Red Team vs. Penetration Testing in 2026: When You Need Each One and What the Difference Actually Costs
Red teaming and penetration testing solve different problems — here's when to use each, what each engagement actually delivers, and why most Indian enterprises are running the wrong one.
Fortinet FortiSandbox OS Command Injection: CVE-2026-25089 & CVE-2026-39808 (CVSS 9.1) Actively Exploited — Patch Now
Two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox are actively exploited for RCE — CISA added both to KEV July 16, patch to 4.4.9 or 5.0.6 immediately.
DPDPA Vendor Risk Management 2026: What Every Data Fiduciary Must Know About Third-Party Processors
India's DPDP Act places binding obligations on data fiduciaries for every vendor they share personal data with — here's the compliance framework before November 2026 enforcement.
Joomla Extensions Under Active Attack: CVE-2026-48908, CVE-2026-48939, CVE-2026-56291 Added to CISA KEV (CVSS 10.0)
Three Joomla extension vulnerabilities with CVSS 10.0 scores are being actively exploited for unauthenticated file upload and RCE — patch now or take systems offline.
DPDPA Data Localisation and Cross-Border Transfer Rules 2026: What Indian Businesses Must Know
India's DPDP Act imposes strict conditions on cross-border data transfers and data localisation — here's what every Indian business must do before November 2026 enforcement.
Dark Web Monitoring in 2026: How 16 Billion Leaked Credentials Fuel Attacks on Indian Businesses
With 16 billion credentials circulating on dark web markets and the average employee leak window under 48 hours, dark web monitoring has become a core component of any serious VAPT programme.