AI Security

OWASP LLM Top 10 2025: Critical Vulnerabilities in Production AI Systems

A comprehensive analysis of the OWASP LLM Top 10 2025 list — from prompt injection to training data poisoning — and how Prava's four dedicated AI security modules close each gap.

Prava Research Team · May 2025 · 8 min read
Full article coming soon

OWASP LLM Top 10 2025
In-depth analysis

Dark Web Intel

What Satyam Found: Credential Markets in Q1 2025

A quarterly deep-dive into credential marketplaces monitored by the Satyam dark web intelligence engine — what changed, what grew, and what organisations should act on.

Satyam Intel Team · 7 min read
Compliance

ISO 27001:2022 vs 2013 — Everything Your GRC Team Needs to Know

The 2022 revision introduced Annex A restructuring, new controls on threat intelligence and cloud security, and a clearer risk-based approach. Here's what changes for your programme.

Prava Research Team · 6 min read
AI Security

Prompt Injection Attacks: From Simple Overrides to Multi-Turn Persistent Exploits

Prompt injection has evolved well beyond "ignore previous instructions." We map the current attack landscape from direct injections to indirect, multi-turn, and stored variants.

Prava Research Team · 9 min read
Vulnerability Research

OWASP API Security Top 10: BOLA, Broken Auth, and What SAST Won't Catch

Static analysis misses the most critical API vulnerabilities. We break down BOLA, broken object-level authorisation, broken auth, and the runtime behaviours that only dynamic testing reveals.

Prava Research Team · 6 min read
Threat Intelligence

Ransomware-as-a-Service in 2025: How RaaS Operations Target Organisations

The affiliate model has industrialised ransomware. We examine Q1 2025 RaaS operations — affiliate toolkits, negotiation playbooks, and initial access broker relationships.

Satyam Intel Team · 8 min read
AI Security

MCP Security: The New Attack Surface Nobody's Talking About

Model Context Protocol (MCP) servers are rapidly becoming privileged orchestration layers for AI agents. Here's why this creates novel attack surfaces — and how to audit them.

Prava Research Team · 5 min read
Compliance

DPDP 2023: What India's New Data Privacy Law Means for SaaS Platforms

The Digital Personal Data Protection Act 2023 introduces significant obligations for SaaS companies handling Indian user data. We break down what you actually need to do.

Prava Research Team · 7 min read
Vulnerability Research

Vehicle Security in 2025: CAN Bus Attacks, V2X Exploits, and ADAS Adversarial AI

Connected vehicles have expanded the automotive attack surface from physical to remote. This deep-dive covers CAN bus injection, V2X protocol exploits, and adversarial attacks against ADAS perception models.

Prava Research Team · 10 min read
Product Update

Prava v3.0: OSINT Module and 30th Compliance Automation Module Now Live

Prava v3.0 ships with the long-awaited OSINT module (M29) and the 30th compliance automation module, bringing the platform's framework coverage to 37 standards.

Prava Team · 4 min read

See the intelligence layer in action.

Explore the Prava platform powering this research, or start your free trial today.

Explore Platform Start Free →