19 posts · updated weekly

Field notes from the diagnostic layer.

Deep-dives on AI readiness, DNS, security, and the small engineering choices that make domain tooling actually trustworthy.

FEATURED
SECURITYSeptember 10, 2026 · 10 min·0

BigBear 2.0 (Sept 2026): 3,331 Microsoft 365 Victims and the End of MFA-Only Defense

CloudSEK exposed the BigBear 2.0 phishing-as-a-service network — 5,137 stolen credential records, 461 organizations across 40+ countries, and 474 fully MFA-authenticated Microsoft 365 sessions hijacked from a fleet of 42 Vultr proxies. Here is why passwords plus MFA no longer stop credential theft, and how infrastructure-level scanning catches the pattern.

SSindhuRead post
Security
ALL POSTS
Security
SECURITYSeptember 10, 2026 · 9 min·0

Diwali 2026 Phishing Playbook: 828 Fake Ad Domains, 1-in-3 Indians Duped, and the UPI + Deepfake Trap

McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before Diwali 2026 — found one in three Indians duped by festive-season scams, 37 percent suffering financial loss, average loss over ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running Facebook Ads campaigns in one festive window. Here is the 2026 playbook — the brands attackers impersonate, the domain patterns Domainscan catches, and the 30-second check to run before every festive payment.

AAvinash
Security
SECURITYSeptember 10, 2026 · 9 min·0

Typosquatting in 2026: 301-Redirect Traps, MX Poisoning, and AI-Generated Cover Pages

CrowdStrike Counter Adversary Ops mapped the 2026 typosquat playbook — 301 redirects that hide the phishing site while the MX record silently steals email, Cloudflare Ray-ID geo-filters that show clean pages to security researchers, and AI-generated "domain for sale" cover art. Bitdefender puts the AI-driven phishing surge at 70 percent. Here are the mechanics and the infrastructure checks that catch them.

SSindhu
Security
SECURITYSeptember 3, 2026 · 9 min·0

86% of Enterprises Hit a Certificate Outage This Year (Keyfactor 2024)

Keyfactor's 2024 PKI & Digital Trust Report: 86% of surveyed organisations logged at least one certificate-related outage in the past 12 months, 31% at least quarterly, ~10% weekly. Only 32% run a formal certificate lifecycle tool. Now compress the renewal cadence 8× under the CA/Browser Forum's 47-day ballot by March 2029 and calculate what breaks first.

RRahul
Security
SECURITYSeptember 3, 2026 · 9 min·0

The 2024 Cost of a Data Breach: $4.88M and Rising

IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88M — up 10% year-over-year, the largest single-year jump since the pandemic. Phishing-initiated breaches averaged $4.76M and the mean time to identify plus contain a breach was 258 days. US average: $9.36M. Healthcare: $9.77M for the fourteenth consecutive year on top. Sector-by-sector breakdown and what "cut detection time" is worth on the invoice.

RRahul
Email Auth
EMAIL AUTHSeptember 3, 2026 · 10 min·0

The DMARC Enforcement Gap: 78% Publish, Only 42% Enforce

Valimail's 2026 State of DMARC pegs publication at 78% of the top million domains, but real enforcement (p=quarantine or p=reject) sits at just 42%. Fortune 500 adoption is 93.8% — yet only 62.7% enforce. p=none protects nobody. Here is why the gap exists, what Google/Yahoo's Feb 2024 bulk-sender rules changed, and the 30-day path from p=none to p=reject.

SSindhu
Security
SECURITYSeptember 3, 2026 · 9 min·0

The Ericsson-O2 SSL Outage: How One Expired Certificate Cost £100M

December 6, 2018. One expired software certificate in Ericsson's SGSN-MME took roughly 32 million O2 UK subscribers offline, plus tens of millions of SoftBank Japan users and customers across 11 countries. O2 later sought approximately £100M in damages. Here is the timeline hour by hour, the root cause SMB teams still miss under the words "auto-renew", and why the CA/Browser Forum's move to a 47-day certificate lifetime by 2029 makes the O2 incident a rehearsal.

AAvinash
Security
SECURITYSeptember 3, 2026 · 10 min·0

The $121M Lookalike-Domain BEC: What Rimasauskas Taught Every CFO

2013–2015. A Lithuanian named Evaldas Rimasauskas registered a lookalike of hardware vendor Quanta Computer, forged invoices, and wired roughly $121M out of Facebook and Google before either company noticed. Arrested 2017. Guilty plea March 2019. Five years plus $49.7M forfeiture, December 2019. Why DMARC at p=reject and a lookalike-domain monitor would have shut the entire scheme down inside a week.

SSindhu
Security
SECURITYSeptember 3, 2026 · 11 min·0

FBI IC3 2024: $2.79B in BEC Losses (and Why That's Only a Fraction)

The FBI Internet Crime Complaint Center's 2024 Annual Report logged 21,442 business email compromise cases totalling roughly $2.79B in reported US losses — bringing the 2022–2024 cumulative to about $8.5B. Total IC3 losses across all crime types hit a record $16.6B. Full breakdown, why the true BEC figure is a multiple of what got reported, and what preventing one incident is actually worth on your books.

TTarun
Security
SECURITYSeptember 3, 2026 · 11 min·0

Watching Only the Apex: How Ignoring Subdomains Turns Into a Six-Figure Incident

Your uptime checks are on example.com. Your SSL monitor is on example.com. Your DMARC alerts fire on example.com. Meanwhile api., staging. and blog. are running unmonitored — and that is exactly where attackers live. Here is what apex-only monitoring misses, why it keeps costing companies money, and how to fix it in an afternoon.

SSindhu
AI
AIJune 26, 2026 · 13 min·0

MCP for AI agents — what Model Context Protocol unlocks, and how live domain intelligence fits in

A plain explanation of MCP, the problem it solves, and the five patterns it unlocks for AI agents — with worked examples of grounding an agent in live WHOIS, DNS, SSL, blacklist and email-auth data.

AAvinash
Security
SECURITYJune 23, 2026 · 9 min·0

Amazon Prime Day 2026: 6,843 Fake Domains and the End of Manual Phishing Detection

Check Point Research flagged 6,843 Amazon-themed domains registered ahead of Prime Day 2026 — one in thirteen explicitly malicious. Industrial-scale phishing now ships with valid SSL. Here is why padlocks no longer save you, and how infrastructure-level scanning does.

SSindhu
Security
SECURITYJune 14, 2026 · 11 min·0

How to Check If a Website Is Safe Before You Pay: 7-Step Verification Guide

Before you type a card number or scan a UPI QR, run a website through these seven checks. Each one takes under a minute, and most fake sites fail at least three of them.

TTarun
Fraud
FRAUDJune 12, 2026 · 10 min·0

Payment Scam Websites: 12 Red Flags Fraudsters Hope You Miss

The exact patterns that show up on fake checkout pages — newly-registered domains, hidden WHOIS, suspicious nameservers, fake trust badges, and the QR-code tricks costing Indians ₹400 crore a year.

RRahul
Domains
DOMAINSJune 9, 2026 · 9 min·0

Lookalike Domains & Typosquatting: How Scammers Hijack Your Checkout

A walkthrough of the URL tricks behind most payment phishing — typo swaps, dash insertions, homograph attacks, and punycode spoofs — with real examples and the WHOIS checks that catch them.

AAvinash
Security
SECURITYJune 6, 2026 · 8 min·0

The HTTPS Padlock Lie: Why SSL Doesn’t Mean a Website Is Safe to Pay On

The padlock icon only proves the connection is encrypted. It doesn’t verify who runs the site. Most phishing pages in 2026 have valid SSL — here’s what to actually check.

SSindhu
Fraud
FRAUDJune 3, 2026 · 10 min·0

Fake Courier & Delivery Scam Sites: The 2026 Playbook (India Post, DHL, FedEx Lookalikes)

Inside the ₹25 redelivery scam: how fraudsters impersonate India Post, DHL, FedEx, and Blue Dart, the SMS hooks they use, the tracking pages they clone, and how to verify a courier URL in under a minute.

SSindhu
AI
AIMay 22, 2026 · 12 min·0

AI Readiness: the new SEO surface area in 2026

Why every domain needs to think about how GPTBot, Claude-Web, and PerplexityBot see it — and the five signals that actually move the needle.

RRahul
AI
AIMay 18, 2026 · 11 min·0

llms.txt explained — a markdown TOC for LLMs

The emerging convention for telling AI systems which of your pages matter most. With examples from GitHub, Anthropic, and Cloudflare.

AAvinash
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.