Dark Web Intel
What Satyam Found: Credential Markets in Q1 2025
A quarterly deep-dive into credential marketplaces monitored by the Satyam dark web intelligence engine — what changed, what grew, and what organisations should act on.
Satyam Intel Team
·
7 min read
Compliance
ISO 27001:2022 vs 2013 — Everything Your GRC Team Needs to Know
The 2022 revision introduced Annex A restructuring, new controls on threat intelligence and cloud security, and a clearer risk-based approach. Here's what changes for your programme.
Prava Research Team
·
6 min read
AI Security
Prompt Injection Attacks: From Simple Overrides to Multi-Turn Persistent Exploits
Prompt injection has evolved well beyond "ignore previous instructions." We map the current attack landscape from direct injections to indirect, multi-turn, and stored variants.
Prava Research Team
·
9 min read
Vulnerability Research
OWASP API Security Top 10: BOLA, Broken Auth, and What SAST Won't Catch
Static analysis misses the most critical API vulnerabilities. We break down BOLA, broken object-level authorisation, broken auth, and the runtime behaviours that only dynamic testing reveals.
Prava Research Team
·
6 min read
Threat Intelligence
Ransomware-as-a-Service in 2025: How RaaS Operations Target Organisations
The affiliate model has industrialised ransomware. We examine Q1 2025 RaaS operations — affiliate toolkits, negotiation playbooks, and initial access broker relationships.
Satyam Intel Team
·
8 min read
AI Security
MCP Security: The New Attack Surface Nobody's Talking About
Model Context Protocol (MCP) servers are rapidly becoming privileged orchestration layers for AI agents. Here's why this creates novel attack surfaces — and how to audit them.
Prava Research Team
·
5 min read
Compliance
DPDP 2023: What India's New Data Privacy Law Means for SaaS Platforms
The Digital Personal Data Protection Act 2023 introduces significant obligations for SaaS companies handling Indian user data. We break down what you actually need to do.
Prava Research Team
·
7 min read
Vulnerability Research
Vehicle Security in 2025: CAN Bus Attacks, V2X Exploits, and ADAS Adversarial AI
Connected vehicles have expanded the automotive attack surface from physical to remote. This deep-dive covers CAN bus injection, V2X protocol exploits, and adversarial attacks against ADAS perception models.
Prava Research Team
·
10 min read
Product Update
Prava v3.0: OSINT Module and 30th Compliance Automation Module Now Live
Prava v3.0 ships with the long-awaited OSINT module (M29) and the 30th compliance automation module, bringing the platform's framework coverage to 37 standards.
Prava Team
·
4 min read