Blog
CERT-In Compliance Consultant — the Six-Hour Clock Is a Design Problem
The six-hour clock starts before you know anything happened Organisations usually come to me about CERT-In’s directions expecting a compliance exercise: forms, a portal registration, a policy document. I stop…
Read More →Virtual CISO Consultant — Senior Security Leadership Without the ₹60 Lakh Hire
Most mid-sized companies have security tools. Almost none have a security owner. I get a version of the same phone call every month. A company of 150, maybe 300 people…
Read More →Zero Trust Consultant in India — Designing Networks That Trust Nothing
Zero trust is not a box you buy Every few months a CIO tells me, “We have bought zero trust.” What they have bought is a licence — sitting in…
Read More →FortiGate Consultant in India — 30 Years on the Security Fabric
What a FortiGate consultant actually does Most FortiGate estates in India were not designed. They were delivered. A reseller quoted the box, a junior engineer racked it, a base config…
Read More →CVE-2026-5430 (CVSS 10.0): WSO2 API Manager JWT Algorithm Confusion Bypass — Attackers Now Forging Admin Tokens in the Wild
CVE-2026-5430 (CVSS 10.0) lets attackers forge admin JWT tokens in WSO2 API Manager without credentials. Active exploitation confirmed September 2026. Patch now.
Read More →CVE-2026-91843 (CVSS 9.8): Check Point Management Server Unauthenticated Root RCE — Your Firewall Console Is the Target
CVE-2026-91843 (CVSS 9.8) gives unauthenticated attackers root access on Check Point Quantum Security Management Server. Learn what's affected, how to patch, and India-specific risks.
Read More →CVE-2026-76460 (CVSS 10.0): Cisco ISE Authentication Bypass Zero-Day Exploited in Wild — CISA Orders Emergency Patch
Cisco ISE zero-day CVE-2026-76460 (CVSS 10.0) allows unauthenticated root RCE and is actively exploited. CISA patch deadline: September 19, 2026. Patch now.
Read More →CVE-2026-51990: China-Linked UNC3569 Exploits Sogou One-Click RCE to Plant GRAYRABBIT Backdoor — Is Your Endpoint Exposed?
China-linked UNC3569 exploited CVE-2026-51990 in Tencent Sogou IME via a one-click RCE chain to deploy the GRAYRABBIT backdoor across East and Southeast Asian targets. Patch or remove Sogou now.
Read More →CVE-2026-82329 (CVSS 9.8): JFrog Artifactory Authentication Bypass Exploited in 24-Day Supply Chain Campaign — Patch Now
CVE-2026-82329, a CVSS 9.8 critical auth bypass in JFrog Artifactory, was exploited 406,000 times in a single day. Attackers planted persistent Rust backdoors that survive patching. Here is what to…
Read More →CVE-2026-19490 (CVSS 9.3): Citrix NetScaler Auth Bypass Exploited in the Wild — Federal Deadline Passed, Are You Still Exposed?
CVE-2026-19490 (CVSS 9.3) actively exploits Citrix NetScaler Gateway. CISA deadline passed. Patch to 14.1-73.32 or 13.1-63.21 now — expert guide.
Read More →