top of page


Mass PII Exposure: How Forgotten Files Can Lead to Critical Data Leakage
Learn how unauthenticated access to sensitive documents can expose thousands of PII records, why file exposure is critical, and how organizations can prevent mass data leakage.
Rajan Kumar Barik
Jun 167 min read


CERT-In’s New AI Cybersecurity Blueprint Sends a Clear Message: Annual Security Assessments Are No Longer Enough
The Indian Computer Emergency Response Team (CERT-In) has released one of its strongest cybersecurity advisories to date, warning organisations that artificial intelligence is fundamentally changing how cyberattacks are executed.
Abhinav Bangia
Jun 13 min read


IRDAI 2026 Guidelines: A Tailwind for Bug Bounty - and a Wake-Up Call for Insurers
The IRDAI Information & Cyber Security Guidelines 2026
Abhinav Bangia
May 42 min read


How to Start a Bug Bounty Program in India: A Step-by-Step Guide for CISOs
Starting a bug bounty program is one of the highest-ROI security investments a CISO can make but only if it is done right. Done wrong, it becomes a triage nightmare, a researcher relations disaster, and a budget black hole. The difference between programs that succeed and those that quietly die within a year almost always comes down to preparation. The organisations that thrive in bug bounty have invested time in their scope, their internal processes, and their relationship w
Ridhi Sharma
Apr 2217 min read


Bug Bounty in 2026 : It is more augmented, more perspective-driven, and more demanding of real ingenuity.
Bug bounty is entering a new phase. Researchers will spend less time on repetitive grunt work and more time on high-value thinking.
Abhinav Bangia
Apr 92 min read


Zeroing Down on Moving IP Targets: Why Traditional Threat Intelligence is Failing — and What Comes Next
Modern infrastructure has changed the meaning of an IP address. A single IP can represent thousands of users through carrier-grade NAT (CGNAT), while a single attacker can rotate across hundreds of IPs using VPNs, mobile networks, or cloud infrastructure.
Abhinav Bangia
Mar 174 min read


Bug Bounty Platforms: What Security Leaders Should Know Before Choosing One
If you are evaluating bug bounty platforms, here is what you should understand before making a decision.
Ridhi Sharma
Feb 214 min read


Bug Bounty Program Readiness Checklist: What Security Leaders Must Do Before Launching
Bug bounty programs get a lot of attention, and for good reason. When they work well, they help organizations uncover real security vulnerabilities that automated tools and internal testing often miss.
Yashika Wadhwani
Feb 194 min read


Non-Negotiables at Com Olho
Com Olho exists to enable responsible, ethical, and effective vulnerability disclosure. To make that possible, we operate with clear boundaries.
Jahanvi Sachdeva
Jan 292 min read


The Role of ISO 29147 and 30111 in Enhancing Cybersecurity Strategies for 2026
Two key international standards, ISO 29147 and ISO 30111, provide essential frameworks for managing vulnerability disclosure and handling.
Jahanvi Sachdeva
Nov 11, 20254 min read


How to Master Time Based SQL Injection Techniques for Ethical Hacking
Among the various SQL injection methods, Time Based SQL Injection is particularly powerful.
Jahanvi Sachdeva
Aug 26, 20254 min read


How to Begin Your Journey in Ethical Hacking for Mobile Applications
Ethical hacking for mobile applications is a thrilling and evolving area that plays a vital role in safeguarding user data.
Aditya Kumar
Jul 29, 20254 min read


Man-in-the-Middle Attacks Demystified: How They Work and How to Stop Them
Think of a Man-in-the-Middle (MITM) attack as someone slipping into a private conversation you’re having — maybe in a café or a quiet...
Aditya Kumar
Jul 14, 20253 min read


Scattered Spider Strikes Aviation: Inside the Triple Airline Cyberattack Spree
In the span of just three weeks, three major airlines—Qantas, WestJet, and Hawaiian Airlines—became victims of sophisticated cyberattacks.
Abhinav Bangia
Jul 3, 20253 min read


Understanding CVE-2024-6387: A P1 Vulnerability Exposing Systems to Remote Code Execution Risks
CVE-2024-6387 has been identified as a P1 vulnerability, a top-priority, high-severity issue that demands immediate attention.
Abhinav Bangia
Nov 12, 20243 min read


The DPDP Act in India and the Role of Bug Bounty Programs in Strengthening Data Security
Given the DPDP Act’s stringent guidelines on security and breach reporting, bug bounty programs can help organisations
Abhinav Bangia
Sep 25, 20243 min read


The Relevance of Bug Bounty Programs in Manufacturing Companies
In this blog, we explore why manufacturing companies should adopt bug bounty programs.
Abhinav Bangia
Sep 25, 20245 min read


The Importance of SSL Pinning for Mobile Apps: Securing Your Data in Transit
App uses SSL pinning, it ensures that it only trusts specific certificates, typically those of the server it is communicating with.
Aditya Kumar
Aug 1, 20243 min read


Why Every Startup Needs a Cybersecurity Strategy
Cybercriminals often target small businesses, including startups, due to their typically weaker security measures.
Aditya Kumar
Jul 11, 20242 min read


Shielding Your WordPress Site:Understanding and Mitigating XML-RPC Vulnerabilities
If you've discovered an XML-RPC vulnerability in your WordPress site, there are several steps you can take to mitigate the risks associated
Anurag Tripathi
May 14, 20242 min read
bottom of page
