Threat Intelligence
Recent CVEs, active exploitation campaigns, threat actor TTPs, IOC analysis.
Recent Ransomware Groups Targeting Indian SaaS in 2026
Active ransomware groups hitting Indian organisations — RansomHub, Akira, Play / 8base / BlackSuit. Common kill chain (initial access via VPN/RDP, Cobalt…
Threat IntelligenceSpring4Shell (CVE-2022-22965): Why It’s Still Hitting Java in 2026
Spring4Shell was disclosed in March 2022. Vulnerable Spring still found in Indian enterprise audits in 2026, particularly legacy Java apps and vendor…
Threat IntelligenceServer-Side Template Injection (SSTI) in 2026: Detection and Exploitation
SSTI test methodology — canary payloads for Jinja2, Twig, Smarty, Freemarker, Velocity, ERB, Razor. Where SSTI hides (email templates, error messages, report…
Threat IntelligencePython Pickle Deserialization: The 20-Year-Old Footgun
Pickle on untrusted input is RCE by design. Where it hides — cache layers, session storage, Celery task arguments, ML models, cookie…
Red TeamingProxyShell: The Exchange Vulnerability That Fueled Ransomware
ProxyShell (CVE-2021-34473/34523/31207) chain — pre-auth RCE on Exchange. Why it became ransomware fuel, IoCs (webshells in Exchange directories, anomalous PowerShell remoting), patching…
Red TeamingDirtyPipe (CVE-2022-0847): Why This 3-Year-Old Linux Kernel CVE Still Hits Indian Production
DirtyPipe was disclosed in March 2022. The fix has been available for three years. Yet 1 in 5 Indian Linux pentests still…
Red TeamingPrintNightmare in 2026: The Bug Class Microsoft Couldn’t Quite Kill
PrintNightmare (CVE-2021-1675/34527) was supposed to die in 2021. Print Spooler bugs continue producing new CVEs every year. The bug, the variants since…
Threat IntelligenceLog4Shell 4 Years Later: Why It’s Still in 15% of Indian Enterprise Audits
Log4Shell (CVE-2021-44228) was disclosed in December 2021. Four years on, 15-20% of Indian enterprise audits still find vulnerable Log4j. The bug, modern…
DPDP ComplianceIncident Response Runbook: Data Exfiltration Under DPDP (India)
Data exfiltration incidents were difficult enough before the DPDP Act 2023. Now they carry statutory teeth: notification obligations to the Data Protection…
Security GuidesIncident Response Runbook: Credential Compromise & Session Hijack
Credential compromise rarely announces itself. Ransomware comes with a note; credential theft comes with a successful login from an unexpected IP, an…