top of page
All Posts


When AI Chatbots Leak Secrets: How Companies Accidentally Train Models on Private Data
SWARNALI GHOSH | DATE: JANUARY 26, 2026 Introduction The rapid integration of Generative AI (GenAI) into enterprise workflows has fundamentally shifted the security perimeter. We aren't just worried about external servers anymore; the new "breach site" is the internal neural weights of the models themselves. As organizations race to adopt these tools for a productivity edge, many are inadvertently creating a "silent archive" of proprietary source code, internal financial dat

Swarnali Ghosh
2 days ago4 min read


Hacking the Metaverse: Virtual Reality as a New Frontier for Cybercrime
SWARNALI GHOSH | DATE: JANUARY 26, 2026 Introduction The essence of the Metaverse has always been about presence: “being there” in a digital space, rather than merely seeing. However, as we delve into 2026, many IT leaders are discovering that presence comes with a cost. Picture a private virtual company boardroom for a high stakes executive meeting. Perhaps an actual meeting, or maybe not so private. A hidden presence lurks in the corner, capturing every movement and murmu

Swarnali Ghosh
3 days ago5 min read


The Rise of Privacy-Enhancing Technologies in 2024
MINAKSHI DEBNATH | DATE: JANUARY 26, 2026 Stuck for ages in a tough spot - choose between using data to spark new ideas or sealing it tight for privacy. Every time, gaining one meant losing the other. Now, maybe, just maybe, that old compromise doesn’t hold weight anymore. One look at the figures shows something big unfolding. Data released by Market.us reveals that worldwide spending on Privacy-Enhancing Technologies reached about $3.17 billion in 2024; this figure could cl

Minakshi DEBNATH
6 days ago4 min read


Quantum Hacking: Exploiting Pre-Quantum Systems Before They’re Ready
MINAKSHI DEBNATH | DATE: JANUARY 23, 2026 We’ve all heard the warnings about "Q-Day" that theoretical point in the future when a quantum computer finally snaps RSA-2048 like a dry twig. But if you're working in enterprise security day-to-day, there's a more pressing yet quieter threat emerging that we can't ignore. It's called Harvest Now, Decrypt Later (HNDL), and here's the unsettling reality: your encrypted data's protection may already have an expiration date. Here’s the

Minakshi DEBNATH
Feb 204 min read


Unmasking the Invisible: Why Attack Surface Management is the Antidote to Cloud Sprawl
SHILPI MONDAL| DATE: JANUARY 23, 2026 The Visibility Gap: What You Don’t See Will Hurt You If you feel like your organization’s digital footprint is expanding faster than your team can track it, you aren’t imagining things. The traditional secure perimeter hasn’t just shifted-it has effectively dissolved into a fragmented landscape of hybrid work, SaaS adoption, and cloud-native microservices. According to the National Institute of Standards and Technology’s (NIST) Special

Shilpi Mondal
Feb 186 min read


The Dark Side of AI-Powered Pen Testing: When Ethical Tools Turn Malicious
SWARNALI GHOSH | DATE: JANUARY 22, 2026 Introduction We’ve officially left the "Artisan Era" of cybersecurity. For decades, penetration testing was a boutique service highly skilled humans manually probing for cracks in the armour. But as we navigate the early weeks of 2026, we’ve hit a critical inflexion point. We are now firmly in the Agentic Era , where AI penetration testing is no longer just a buzzword; it’s the primary engine for both the hunters and the hunted.

Swarnali Ghosh
Feb 134 min read


Ransomware Attacks on 3D-Printed Medical Implants: A Life-Threatening Cybercrime
SWARNALI GHOSH | DATE: JANUARY 21, 2026 Introduction Consider a surgeon preparing for a complex spinal reconstruction in which the centrepiece is a custom-made titanium implant, printed to the exact specification of the patient's anatomy. But what if that implant contains a microscopic, invisible defect-a hollowed-out void programmed into the G-code by a remote attacker? Even more chilling: what if the hospital doesn't know until a ransom note appears, claiming that 10% of

Swarnali Ghosh
Feb 114 min read


Security in Decentralized Identity (DID) Systems & Blockchain
SHILPI MONDAL | DATE: JANUARY 20, 2026 We are witnessing the slow, painful death of the traditional perimeter security model. If 2023 taught us anything, it’s that centralizing identity data is akin to painting a target on your back. With data breaches exposing over 4.1 billion digital records in a single year, the message to enterprise leaders is clear: the "castle and moat" strategy isn't just failing; it’s becoming a liability. At AmeriSOURCE, we’ve seen a significant

Shilpi Mondal
Feb 96 min read


Acoustic Side-Channel Attacks: Stealing Data by Listening to Your Computer's Fan or HDD
SHILPI MONDAL | DATE: JANUARY 19, 2025 For decades, the "air gap" has been the gold standard for enterprise security. The logic is simple and seemingly foolproof: if a critical system is physically isolated from the internet-cables cut, Wi-Fi disabled, Bluetooth removed-it cannot be hacked remotely. But here is the uncomfortable truth keeping C-suite leaders up at night: physics doesn't care about your network policies.Even when a computer is disconnected from the digital wor

Shilpi Mondal
Feb 66 min read


Living off the Land Attacks (LotL): When Hackers Use Your Tools Against You
SHILPI MONDAL | DATE: JANUARY 09 , 2026 We used to worry about "files." In the old days, and by that , I mean just a few years ago, defense was largely about spotting the anomaly on the disk. A strange .exe, a malicious payload, a signature that didn't match the known good. But the game has changed entirely. Why would an attacker spend time and money developing custom malware that might get flagged by your antivirus when they can simply use the tools you’ve already paid for

Shilpi Mondal
Feb 46 min read


Post-Quantum Cryptography: Is Your Data Ready for the “Harvest Now” Threat?
SHILPI MONDAL | DATE: JANUARY 09 , 2026 The Quantum Clock is Ticking Louder Than You Think Imagine a burglar who can’t pick your safe today, so they simply steal the entire safe and wait for a better drill to be invented. This isn't a hypothetical scenario; it is the exact reality of the "Harvest Now, Decrypt Later" (HNDL) threat facing enterprise data right now. With recent breakthroughs pushing us closer to fault-tolerant quantum computing, the "theoretical" risk has of

Shilpi Mondal
Feb 27 min read


The Growing Threat of OAuth Token Abuse
SHILPI MONDAL | DATE: JANUARY 02 ,2026 Remember when a strong firewall and a complex password meant a good night's sleep? Those days are gone. We’ve seen a fundamental shift in how adversaries operate, moving away from banging on the digital front door of hardware perimeters to quietly subverting the very identity frameworks we rely on for "seamless" connectivity. At the heart of this shift is the OAuth 2.0 protocol. It’s the ubiquitous plumbing for our SaaS integrations, t

Shilpi Mondal
Jan 285 min read


Voice Cloning for Corporate Espionage: The New Frontier in BEC Threats
SHILPI MONDAL| DATE: DECEMBER 23, 2025 The scenario is no longer the plot of a spy thriller; it is a Monday morning reality for modern finance departments. A regional controller receives a call from the Group CFO. The cadence is perfect, the slight impatience in the tone is familiar, and the request an urgent, confidential wire transfer to secure a competitive acquisition is logically sound. Without hesitation, the controller bypasses standard protocol, believing they are act

Shilpi Mondal
Jan 276 min read


The Case for a Global Cybercrime Interpol: Can AI-Powered Policing Scale?
SWARNALI GHOSH | DATE: JANUARY 12, 2026 Introduction The high-speed arms race of the digital age has reached a mirror-smooth track where the margin for error is effectively zero. In this landscape, the "defender" must protect every single inch of the infrastructure, while an attacker now bolstered by autonomous algorithms only needs to find one microscopic crack to cause a total system crash. As we sit here in early 2026, the question for CIOs and IT leaders isn't just abo

Swarnali Ghosh
Jan 224 min read


The Underground Market for Zero-Day Exploits: Who’s Buying & Selling?
SWARNALI GHOSH | DATE: JANUARY 05, 2026 Introduction A potential zero-day exploit may be thought of as a master key used by a thief if the given software flaw were conceived as an unlocked door of a car. By the year 2026, that thief has several accomplices since he is a member of an industrialized locksmith factory that produces and delivers the master key all over the globe in just hours upon locating the lock. The stakes for the modern C-Suite have never been higher. W

Swarnali Ghosh
Jan 195 min read


Website Fingerprinting: How Tor and VPN Users Can Still Be Tracked
SHILPI MONDAL | DATE: JANUARY 13 ,2025 If you think your organization is invisible because you force all remote traffic through an encrypted tunnel, you might want to reconsider that assumption. We tend to visualize encrypted connections whether via a corporate VPN or the Tor network as opaque pipes that shield us from prying eyes. The payload is indeed scrambled; a math-based lock keeps the actual data unreadable. But there’s a catch. While the “what” is hidden, the “how”

Shilpi Mondal
Jan 146 min read


"Shadow AI” in Security Teams: The Hidden Risk of Unapproved LLM Tools in the SOC
SHILPI MONDAL| DATE: NOVEMBER 25,2025 What “Shadow AI” Actually Is Shadow AI is the use of AI tools especially generative AI and large language models (LLMs) without approval, monitoring, or governance from IT or security. Think of it as Shadow IT 2.0: Instead of unsanctioned SaaS, it’s unsanctioned AI copilots, browser extensions, and LLM chatbots. Instead of “rogue” CRMs, you now have “rogue” model endpoints quietly ingesting sensitive data. Recent research shows how deep t

Shilpi Mondal
Dec 12, 20259 min read


The Danger of 'AI-Generated Superstitions': Training Employees to Ignore Real Alerts
MINAKSHI DEBNATH | DATE: July 18,2025 In today’s digital age, organizations increasingly rely on artificial intelligence (AI) to monitor systems, flag anomalies, and generate alerts across cybersecurity, finance, healthcare, and operations. While AI offers unmatched analytical capabilities, it also presents a growing concern: AI-generated superstitions false or exaggerated alerts that condition employees to ignore or distrust real warnings. What Are "AI-Generated Superstition

Minakshi DEBNATH
Dec 3, 20256 min read


Cybersecurity in Holographic Communication: Protecting 3D Telepresence Systems
SWARNALI GHOSH | DATE: JUNE 09, 2025 Introduction: The Rise of Holographic Communication Imagine attending a business meeting where your colleague, thousands of miles away, appears as a lifelike 3D hologram in your office. This is no longer science fiction—holographic communication is rapidly transforming how we interact, collaborate, and conduct business. Powered by artificial intelligence (AI), augmented reality (AR), 5G/6G networks, and advanced optics, holographic communi

Swarnali Ghosh
Dec 3, 20256 min read


AI-Powered Environmental Surveillance: Protecting Wildlife from Cyber Threats
SHILPI MONDAL| DATE: JUNE 19,2025 Introduction As the digital age advances, so do the threats facing our planet’s wildlife. While artificial intelligence (AI) has emerged as a powerful tool in conservation helping track endangered species, combat poaching, and monitor ecosystems it also introduces new vulnerabilities. Cyber threats, including data breaches, AI model manipulation, and unauthorized surveillance, now pose significant risks to wildlife protection efforts. This

Shilpi Mondal
Nov 27, 20255 min read
bottom of page

