VAPT · 24 articles

VAPT

Penetration testing methodology, scoping guides, reporting, practitioner playbooks.

News

SimpleHelp RMM Auth Bypass CVE-2026-48558 (CVSS 10.0) Exploited in MSP Supply-Chain Attacks

Attackers are actively exploiting CVE-2026-48558, a maximum-severity authentication-bypass flaw (CVSS 10.0) in SimpleHelp’s Remote Monitoring and Management (RMM) software, to deploy the…

Jul 6, 2026 · 2 min read
VAPT

India Banking API Attack Surge: Why Vendor Ransomware Now Threatens UPI Uptime

Why India banking API attacks and vendor ransomware now threaten UPI uptime, and the concrete defence agenda for fintech and NBFC security…

Jun 17, 2026 · 10 min read
VAPT

Vulnerability Disclosure Programs in India: A 2026 Setup Guide

How to set up a vulnerability disclosure program in India in 2026: VDP vs bug bounty, the IT Act safe-harbour angle, and…

Jun 17, 2026 · 9 min read
News

Apache HTTP/2 CVE-2026-23918: Double-Free RCE

May 30, 2026 · 1 min read
News

Cisco SD-WAN CVE-2026-20182 Zero-Day (10.0)

May 30, 2026 · 1 min read
VAPT

Business Logic Flaws: The High-Impact Bugs Scanners Will Never Find

No scanner finds a logic flaw. They are also where the real money is lost. The patterns to test for.

May 25, 2026 · 1 min read
Cloud Security

VAPT in CI/CD: Shifting Penetration Testing Left in 2026

You deploy daily; annual VAPT tests a snapshot that no longer exists. Here is how to shift testing into the pipeline.

May 25, 2026 · 1 min read
AI Security

AI-Enhanced VAPT: How Human + Machine Red Teaming Works in 2026

AI does the tireless enumeration; humans do the creative exploitation. How AI-enhanced VAPT actually works.

May 25, 2026 · 1 min read
Cloud Security

Cloud Misconfigurations: The 60% Problem (IAM, Storage, Keys, Gateways)

Most cloud breaches are not exotic — they are misconfigurations. The 60% problem, and the checks to fix it.

May 25, 2026 · 1 min read
Cloud Security

AWS IAM Privilege Escalation: Real Attack Paths and How to Find Them

In AWS, identity is the perimeter — and IAM privesc is how attackers take the account. The paths to hunt for.

May 25, 2026 · 1 min read