Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
AI Tool Integrations Expose New Attack Surface: Inside MCP Security Risks
Model Context Protocol (MCP), the emerging standard that lets AI assistants connect to external tools and data sources, is rapidly becoming a…
DPDP ComplianceDPDP Significant Data Fiduciary Rules: What Indian Businesses Must Prepare For
India’s Ministry of Electronics and Information Technology (MeitY) has been expected to finalise the rules under the Digital Personal Data Protection (DPDP)…
NewsEdge Device Exploitation: VPN and Firewall Appliances Remain Top Initial Access Vector in 2026
Network edge appliances — VPN gateways, firewalls, load balancers, and SSL inspection proxies — have become the most reliable initial access vector…
NewsPost-Quantum Migration Window Narrows: What NIST FIPS 203 Means for Indian Enterprises
NIST published its first post-quantum cryptography standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — in August 2024.…
Cloud SecurityGitHub Actions Supply Chain Attacks: How CI/CD Pipelines Became the New Target
Software supply chain attacks via CI/CD pipelines have moved from headline-grabbing incidents to a reliable, repeatable attack category. The pattern has evolved…
Mobile PentestAndroid June 2026 Zero-Day: What the Latest Exploited Flaw Means for Enterprise Mobile
Google patched ~124 Android flaws in June 2026, including one exploited zero-day. Why mobile is enterprise attack surface and how to enforce…
Security GuidesGogs Git Zero-Day: A Self-Hosted RCE That Turns Internal Dev Tools Into Entry Points
A critical Gogs RCE zero-day lets a low-privileged user run code on the server holding your source. Heres what self-hosting teams must…
Cloud SecurityCloud Control-Plane Attacks: The 2026 Post-Breach Playbook That Kills Your Logging
After initial access, 2026 attackers pivot to your cloud control plane: minting IAM persistence and killing CloudTrail logging. Here is the kill…
VAPTIndia Banking API Attack Surge: Why Vendor Ransomware Now Threatens UPI Uptime
Why India banking API attacks and vendor ransomware now threaten UPI uptime, and the concrete defence agenda for fintech and NBFC security…
Threat IntelligenceThe Gentlemen: Inside the Fastest-Rising Ransomware-as-a-Service Operation of 2026
The Gentlemen rose to the second most active ransomware operation of 2026 on a 90/10 affiliate split and FortiGate exploits. What Indian…