Pramood Waikar

SEBI CDSL penalty order July 2026 infographic by Skeletos IT Services showing one year of accumulated drift from November 2021 to November 2022, four cybersecurity failures including ADFS server not classified as critical, VAPT exclusion, admin account non-expiring password and DR site already infected by LockBit 3.0 ransomware, resulting in 46-hour settlement disruption and Rs 1 crore SEBI penalty with foreseeable outcome judgment establishing new standard for all SEBI-regulated market infrastructure entities.

SEBI Called It a Foreseeable Outcome. That Phrase Should Change Every CISO’s Vocabulary in India’s Capital Markets.

On the Morning of 18th November 2022, the SEBI-registered Central Depository Services (India) Limited (CDSL) operations team discovered that several of their servers and end-user computers were inaccessible. The malware had already spread. CDSL isolated its systems, disconnected the network, and began damage assessment. The malware was identified as LockBit 3.0 ransomware, one of the …

SEBI Called It a Foreseeable Outcome. That Phrase Should Change Every CISO’s Vocabulary in India’s Capital Markets. Read More »

RBI Commercial Banks Cybersecurity Technology Risk Resilience and Assurance Framework Directions 2026 effective July 31 2026 — Skeletos IT Services infographic showing 10 mandatory requirements including Board oversight, IT Strategy Committee at Board level, independent CISO, DAKSH incident reporting within 6 hours, 19 baseline controls, 24x7 CSOC, third-party ASP obligations, IPv6 assurance, risk management and IS audit with key action points for CTOs and CISOs of Indian commercial banks.

RBI’s New Cybersecurity Framework Is Effective from July 31, 2026. It Is Not Guidance. It Is a Rulebook.

On July 31, 2026, a new regulatory document came into force that every commercial bank operating in India needed to have read by the time it woke up that morning. The RBI (Commercial Banks) Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 is not a circular updating a previous position. It is not a …

RBI’s New Cybersecurity Framework Is Effective from July 31, 2026. It Is Not Guidance. It Is a Rulebook. Read More »

OpenAI AI agent autonomous cyberattack on Hugging Face July 2026 — editorial illustration showing AI model escaping sandbox, chaining zero-day vulnerabilities, and breaching Hugging Face production infrastructure to steal ExploitGym benchmark answers, representing the first documented case of autonomous AI sandbox escape and real-world attack.

The AI Did Not Go Rogue. It Did Exactly What It Was Told. The OpenAI Incident and What It Means for Every CTO Deploying AI Agents.

On a Friday in mid-July 2026, the engineering team at Hugging Face noticed something unusual in their infrastructure. An attacker was inside their systems. A sophisticated one. Over the previous 2.5 days, it had carried out more than 17,600 distinct actions across their internal clusters. It had escalated privileges. Harvested credentials. Moved laterally through cloud …

The AI Did Not Go Rogue. It Did Exactly What It Was Told. The OpenAI Incident and What It Means for Every CTO Deploying AI Agents. Read More »

Bank of Baroda data breach July 2026 — infographic showing how phishing email led to compromised employee desktop and stolen credentials causing cyber breach of customer records, loan papers and audit reports, alongside Skeletos solution showing core banking isolation, CERT-In reporting, email security, employee vigilance and continuous monitoring for Indian banks.

One Email. One Weak Password. India’s Biggest Banking Breach of 2026 Started Here.

On July 24, 2026, a threat actor group called TripleX posted what it claimed was approximately one terabyte of Bank of Baroda customer data on the dark web. For free. Not as a ransom demand. As a statement about the bank’s security posture. The dataset, reviewed by independent security researchers who found the samples credible, …

One Email. One Weak Password. India’s Biggest Banking Breach of 2026 Started Here. Read More »

Incident response plan blog cover showing a locked IR document with disconnected contacts and encrypted credentials on the left, a countdown clock showing the 6-hour CERT-In reporting window in the center, and a tested IR capability checklist on the right, representing India's incident response preparedness gap.

You Have a Firewall, a VAPT Report, and a Policy Document. What You Do Not Have Is a Tested Incident Response Plan.

I got this story from one of our new onboard clients. One of the IT team members called the IT Manager and Director at 2:30 in the morning. Ransomware attacked, and it’s spreading across the server environment. The IT team had detected it eighteen minutes earlier. Two servers were already encrypted. Three more were showing …

You Have a Firewall, a VAPT Report, and a Policy Document. What You Do Not Have Is a Tested Incident Response Plan. Read More »

Kudankulam nuclear power Reactor plant contractor data breach July 2026 — editorial diagram showing protected nuclear security perimeter connected to breached Reliance Infrastructure server at Yotta data centre, with data flowing to World Leaks dark web ransomware group.

The Reactor Was Secure. The Blueprint Was Not. What the Kudankulam Breach Reveals About Critical Infrastructure Contractor Security.

The Kudankulam Nuclear Power Plant in Tamil Nadu has not been hacked. That sentence needs to be established first, clearly and without qualification, before anything else is discussed. The operational systems of India’s largest nuclear facility, including the reactor cores, the control systems, and the infrastructure supplied by Russia’s state-owned Rosatom, are isolated from the …

The Reactor Was Secure. The Blueprint Was Not. What the Kudankulam Breach Reveals About Critical Infrastructure Contractor Security. Read More »

RBI IT Governance Master Directions 2024 compliance guide blog cover showing seven chapter structure, ITSC CCMP VAPT obligations, and 12-week compliance sprint for Indian banks and NBFCs.

The RBI Said This in April 2024. Most Indian Banks and NBFCs Have Not Done It Yet

A few months ago, I was sitting across from the IT head of a mid-size NBFC in Mumbai. A decent-sized company. Upper-middle layer under RBI’s Scale-Based Regulation. A team that takes its work seriously. We were reviewing their security posture when I asked a straightforward question: “Have you constituted your Board-level IT Strategy Committee?” He …

The RBI Said This in April 2024. Most Indian Banks and NBFCs Have Not Done It Yet Read More »

Bajaj Auto ransomware attack June 23 2026 editorial cover showing factory floor screens turning red as ransomware spreads from IT systems through BATL technology subsidiary toward production operations, representing the IT/OT security gap in Indian manufacturing.

The Attack Was on IT. The Risk Was on the Factory Floor. What the Bajaj Auto Ransomware Reveals About India’s Manufacturing Cyber Gap.

Tuesday, June 23, 2026. 8:00 AM IST. A new shift was beginning at one of India’s largest vehicle manufacturers. Workers arriving. Systems booting up. The familiar rhythm of a production day starting. That is when Bajaj Auto’s security team detected it. Ransomware, already active, spreading through the company’s IT infrastructure. Not at 3 AM. Not …

The Attack Was on IT. The Risk Was on the Factory Floor. What the Bajaj Auto Ransomware Reveals About India’s Manufacturing Cyber Gap. Read More »

Supply chain network diagram showing Tata Electronics as the breached center node connected to Apple and Tesla, with World Leaks ransomware group stealing 630GB of trade secrets including iPhone manufacturing specs and Tesla engineering documents in June 2026.

630 GB. 200,000 Files. Apple and Tesla Trade Secrets. What the Tata Electronics Breach Means for Every Indian Manufacturer.

Somewhere in a factory in Tamil Nadu, assemblers are building iPhones. The process is precise, regulated, documented to an extraordinary degree. Quality inspection standards for circuit board components. Material specifications. Assembly procedures. Standard operating procedures for every machine on the floor. This documentation exists because Apple requires it. Because building one-third of the world’s most …

630 GB. 200,000 Files. Apple and Tesla Trade Secrets. What the Tata Electronics Breach Means for Every Indian Manufacturer. Read More »

ShinyHunters claimed 2.2 million Kodak records in June 2026 through a SaaS misconfiguration, not a firewall breach. Blog cover for the Skeletos IT Services breakdown of the Kodak data breach and what Indian CTOs must do now.

2.2 Million Records. No Forced Entry. What the Kodak Breach Tells Every CTO About Their SaaS Stack.

On June 16, 2026, a message appeared on a dark web extortion portal. The target was Eastman Kodak Company. 130 years old. 79,000 patents. One billion dollars in annual revenue. A company that most people still associate with the yellow film boxes their parents used to buy, but which today operates as a serious business-to-business …

2.2 Million Records. No Forced Entry. What the Kodak Breach Tells Every CTO About Their SaaS Stack. Read More »