Knowledge Hub

Practitioner-grade cybersecurity content

Technical playbooks, war stories, and how-to-think guides — written by practitioners, anchored to the Indian context.

Want structured, step-by-step learning instead? Explore the Academy (guided courses) or the AI security hub.

Latest articles

Most recent practitioner playbooks across every track. Filter by topic in the sidebar, or use search.

Academy

Module 3 · Designing Consent UX

Most DPDP compliance failures don’t happen at the database layer or the security layer — they happen at the pixel layer. A…

Apr 19, 2026 · 11 min read
Academy

Module 2 · Data Mapping Workshop

Every DPDP compliance failure begins with the same sentence: “We didn’t know we had that data.” Data mapping is the discipline of…

Apr 19, 2026 · 11 min read
Academy

Module 1 · DPDP Act Foundations

You’ve heard the name. “DPDP Act.” Somebody in your organisation has mentioned it in a meeting. Maybe legal sent a memo. Maybe…

Apr 19, 2026 · 13 min read
Academy

Networking Fundamentals — OSI, TCP/IP, and Why Layers Actually Matter

OSI is a teaching model. TCP/IP is what actually runs on the wire. Most "OSI questions" in interviews are really about how…

Apr 19, 2026 · 12 min read
News

Kudankulam Nuclear Power Plant Cyberattack 2019 — DTrack Malware in India’s Critical Infrastructure: Anatomy of the Lazarus-Linked Intrusion

In October 2019, malware later attributed to North Korea's Lazarus Group was found in administrative networks at Kudankulam Nuclear Power Plant in…

Apr 19, 2026 · 13 min read
Academy

Module 8 · API Security (OWASP API Top 10)

OWASP API Top 10 in practice, GraphQL testing, gRPC, SSRF, LLM-integrated API attacks. The 2026 API attack surface. Pro module.

Apr 19, 2026 · 12 min read
Academy

Module 7 · Business Logic Flaws

Race conditions, workflow manipulation, price/quantity attacks, coupon abuse, TOCTOU. The findings scanners cannot find. Pro module.

Apr 19, 2026 · 13 min read
Academy

Module 6 · IDOR & Authorization Bypass

Horizontal and vertical IDOR, mass assignment, multi-tenant boundary violations, GraphQL authorization. The highest-yield SaaS bug class. Pro module.

Apr 19, 2026 · 13 min read
Academy

Module 5 · Cross-Site Scripting (XSS) in 2026

Reflected, stored, and DOM-based XSS in 2026. Filter bypasses, CSP deep-dive, and the real impact beyond alert(1). Pro module.

Apr 19, 2026 · 11 min read
Academy

Module 4 · SQL Injection in 2026

How SQLi works at the query level, UNION-based extraction, blind SQLi (boolean and time), out-of-band exfiltration, NoSQL injection, sqlmap practice.

Apr 19, 2026 · 13 min read
1 84 85 86 87 88 91