Pramood Waikar

A single OAuth consent click let an attacker read and send email

It Took 03 Days to Find Out What That Click Had Done With OAuth

It started with an email that looked like nothing at all. A member of the sales and marketing team at a midsize insurance backend services company in India clicked a link. The link led to what looked like a normal Microsoft sign-in page. A box appeared asking for permission to connect a productivity app to …

It Took 03 Days to Find Out What That Click Had Done With OAuth Read More »

That Sentence Is a DPDP Problem | Skeletos.

“We Already Have the Data. Let Us Feed It to the AI.” Why That Sentence Is a DPDP Problem

Rajan was genuinely excited. He is the CTO at a mid-size Gold Loan Company in Pune. Sharp, well-read, someone who follows global technology trends closely. We were sitting in his office last quarter when he pulled up a presentation from a vendor he had been speaking with for three weeks. The pitch was for an …

“We Already Have the Data. Let Us Feed It to the AI.” Why That Sentence Is a DPDP Problem Read More »

The Security Layer Most NBFC Build Last | Skeletos

The Security Layer Most NBFC’s Build Last. It Should Be First.

A few months ago, I was sitting in a security review meeting with the IT head of a mid-size NBFC in Pune. They had invested thoughtfully in their security stack. A next-generation firewall from a reputable vendor. Endpoint detection and response is deployed across every managed laptop and desktop. A SIEM feeds alerts to a …

The Security Layer Most NBFC’s Build Last. It Should Be First. Read More »

Your Phone Was Used Against You. Here Is Exactly What to Do Next.

Your Phone Was Used Against You. Here Is Exactly What to Do Next.

It started with a Phone message that looked completely ordinary. A link that promised a job application form. A notification from what appeared to be a courier company asking you to update a delivery address. A QR code shared in a WhatsApp group by someone you thought you knew. You tapped it. Within minutes, an …

Your Phone Was Used Against You. Here Is Exactly What to Do Next. Read More »

The Employee Login Credentials That Nobody Deleted

The Login That Nobody Deleted. How Stale Credentials Are Becoming India’s Fastest-Growing Cyber Threat.

On the morning of March 29, 2025, members of five major Australian superannuation funds woke up to find their retirement accounts had been accessed overnight. Not by a single attacker hitting a single fund with a sophisticated exploit. By a coordinated campaign that hit AustralianSuper, Rest Super, Hostplus, Australian Retirement Trust, and Insignia Financial simultaneously. …

The Login That Nobody Deleted. How Stale Credentials Are Becoming India’s Fastest-Growing Cyber Threat. Read More »

Two Banks. One Vendor. One Day. | Skeletos

2 Banks 1 Vendor. The Third-Party Risk Pattern Indian NBFCs Cannot Ignore.

On April 20, 2026, the Everest Ransomware Group posted the names of two banks on its dark web leak site. Both were major banks. Both appeared on the same day. Both had their customer and document data offered for sale to the highest bidder in criminal markets. The two banks had not been breached separately …

2 Banks 1 Vendor. The Third-Party Risk Pattern Indian NBFCs Cannot Ignore. Read More »

AI Is Costing More Than the Employees It Replaced

AI Is Costing More Than the Employees It Replaced. Here Is What Indian CTOs Are Not Measuring.

In December 2025, the company rolled out Anthropic’s Claude Code (AI) to roughly 5,000 engineers. Within weeks, adoption was extraordinary. By spring 2026, 95% of engineers were using AI tools monthly. Around 70% of code commits were AI-driven. Usage of agentic AI features surged from 32% in February to 84% by March 2026. Lexology By …

AI Is Costing More Than the Employees It Replaced. Here Is What Indian CTOs Are Not Measuring. Read More »

Who Controls Your Employee Data | Skeletos

Who Actually Controls Your Employee Data? If the Answer Is Your Vendor, Read This.

On February 27, 2024, a hacker got into VeriSource Services, a US-based HR and employee benefits administration platform. The attacker was inside the system for one day before unusual activity was detected. By then, the employee data was already gone. Four million employee records. Names. Home addresses. Dates of birth. Gender. Government identification numbers. Employees …

Who Actually Controls Your Employee Data? If the Answer Is Your Vendor, Read This. Read More »

NBFC Bank DPDP Act | Skeletos

The Clock Is Running. What Indian Banks and NBFCs Must Do Before the DPDP Act Bites.

In 2024, a major Indian insurance (NBFC) company discovered a problem it did not create. A third-party service provider it had engaged exposed nearly six lakh customer records on a dark web forum. Names. Email addresses. Mobile numbers. Policy details. The kind of information that, in the wrong hands, enables identity fraud, targeted scams, and …

The Clock Is Running. What Indian Banks and NBFCs Must Do Before the DPDP Act Bites. Read More »

adobe bpo breach Cybersecurity Skeletos

1 Laptop in BPO Office That Became Adobe’s Worst Nightmare

It started with one email, and Adobe lost $13 million of customer records Not a sophisticated zero-day exploit. Not a nation-state attack with custom malware. Just a regular-looking email sitting in the inbox of a support desk employee at an Indian BPO company, somewhere in an office very much like ones you might walk past …

1 Laptop in BPO Office That Became Adobe’s Worst Nightmare Read More »