Practitioner-grade cybersecurity content
Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.
Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.
Latest articles
Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.
Module 3 · Designing Consent UX
Most DPDP compliance failures don’t happen at the database layer or the security layer — they happen at the pixel layer. A…
AcademyModule 2 · Data Mapping Workshop
Every DPDP compliance failure begins with the same sentence: “We didn’t know we had that data.” Data mapping is the discipline of…
AcademyModule 1 · DPDP Act Foundations
You’ve heard the name. “DPDP Act.” Somebody in your organisation has mentioned it in a meeting. Maybe legal sent a memo. Maybe…
AcademyNetworking Fundamentals — OSI, TCP/IP, and Why Layers Actually Matter
OSI is a teaching model. TCP/IP is what actually runs on the wire. Most "OSI questions" in interviews are really about how…
NewsKudankulam Nuclear Power Plant Cyberattack 2019 — DTrack Malware in India’s Critical Infrastructure: Anatomy of the Lazarus-Linked Intrusion
In October 2019, malware later attributed to North Korea's Lazarus Group was found in administrative networks at Kudankulam Nuclear Power Plant in…
AcademyModule 8 · API Security (OWASP API Top 10)
OWASP API Top 10 in practice, GraphQL testing, gRPC, SSRF, LLM-integrated API attacks. The 2026 API attack surface. Pro module.
AcademyModule 7 · Business Logic Flaws
Race conditions, workflow manipulation, price/quantity attacks, coupon abuse, TOCTOU. The findings scanners cannot find. Pro module.
AcademyModule 6 · IDOR & Authorization Bypass
Horizontal and vertical IDOR, mass assignment, multi-tenant boundary violations, GraphQL authorization. The highest-yield SaaS bug class. Pro module.
AcademyModule 5 · Cross-Site Scripting (XSS) in 2026
Reflected, stored, and DOM-based XSS in 2026. Filter bypasses, CSP deep-dive, and the real impact beyond alert(1). Pro module.
AcademyModule 4 · SQL Injection in 2026
How SQLi works at the query level, UNION-based extraction, blind SQLi (boolean and time), out-of-band exfiltration, NoSQL injection, sqlmap practice.