Blog

August 3, 2026

Threat Actor Profile – Qilin

Threat Intelligence

Executive Summary: Qilin (formerly Agenda) is a financially motivated Ransomware-as-a-Service (RaaS) group that has been active since 2022. The group operates a mature affiliate program that provides ransomware payloads, negotiation support, data leak infrastructure, and additional services such as legal…

Read More

July 30, 2026

Bank of Baroda Data Leak: Analysis of the Triple X Extortion Claim and Exposed Customer Data

Threat Intelligence

Executive Summary In May 2026, the threat actor group Triple X claimed responsibility for a significant data breach involving Bank of Baroda (BoB), one of India’s largest public sector banks. The actor published the alleged stolen data on its data leak…

Read More

July 7, 2026

Threat Actor Profile – TeamPCP

Threat Intelligence

Executive Summary TeamPCP is a financially motivated cybercriminal group that emerged in late 2025 and rapidly evolved into a significant threat targeting cloud-native environments and software supply chains. Unlike traditional ransomware groups that primarily rely on network intrusions…

Read More

June 1, 2026

Healthcare Data Breach: Qilin Ransomware Targets CLINICA AVELLANEDA MEDICAL CENTER

Threat Intelligence

On May 16, 2026, the Qilin ransomware group claimed responsibility for a cyberattack against CLINICA AVELLANEDA MEDICAL CENTER in Argentina. According to information published on the group's leak site, attackers allegedly exfiltrated sensitive patient information, including personally identifiable information (PII) and medical imaging reports.

Read More

June 1, 2026

Megalodon Malware Found in 2,800+ GitHub Files Through Malicious GitHub Actions Workflows

Threat Intelligence

A large-scale software supply chain campaign dubbed Megalodon leveraged malicious GitHub Actions workflow modifications to steal sensitive credentials from affected repositories. Analysis revealed credential harvesting capabilities targeting GitHub tokens, cloud credentials, API keys, database secrets, and private keys.

Read More

May 25, 2026

GitHub Internal Repository Breach Claimed by TeamPCP Following VS Code Extension Compromise

Threat Intelligence

Executive Summary: A suspected compromise involving a malicious VS Code extension has led to unauthorized access to GitHub internal repositories, with threat actor TeamPCP claiming to possess nearly 4,000 repositories allegedly stolen from the platform. The threat actor advertised the alleged…

Read More

May 12, 2026

Investigating the Alleged Polymarket Data Exposure

Threat Intelligence

Executive Summary On April 28, 2026, the threat actor identified as XORCAT claimed responsibility for an alleged large-scale data exposure involving the decentralized prediction market platform Polymarket. According to the actor, the incident involved a significant API-related exposure affecting…

Read More

May 7, 2026

Analyzing the Alleged Udemy Data Leak Claimed by ShinyHunters

Threat Intelligence

Executive Summary On April 26, 2026, the threat actor ShinyHunters claimed responsibility for a major data breach, alleging the exposure of over 1.4 million records. This incident highlights ongoing risks from financially motivated cybercriminal groups targeting large datasets, underscoring…

Read More

April 29, 2026

Herth+Buss Data Leak Claimed by Qilin Ransomware: Exposure of Financial and Identity Data

Threat Intelligence

Ransomware groups continue to prioritize organizations within global supply chains, where access to financial systems, partner data, and cross-border operations significantly increases monetization opportunities. The recent claim involving Herth+Buss highlights how threat actors are leveraging data exfiltration to…

Read More

April 29, 2026

ADT Inc. Data Breach: Analysis of a Suspected ShinyHunters Data Extortion Campaign

Threat Intelligence

Executive Summary : ADT Inc. disclosed unauthorized access to a subset of customer data, while a threat actor identified as ShinyHunters claimed responsibility for a significantly larger breach involving over 10 million records. The incident evolved into a data…

Read More

April 24, 2026

Vercel Data Exposure Attributed to ShinyHunters Following Infostealer-Driven Third-Party Compromise

Threat Intelligence

Executive Summary A multi-stage intrusion involving Context AI and Vercel has been identified, leading to alleged data exposure and monetization activity attributed to ShinyHunters. The incident originated from a confirmed Lumma Stealer infection on a Context AI employee system, enabling credential theft…

Read More

April 6, 2026

Anthropic Claude Code Leak: From Accidental Exposure to Open-Source Frenzy

Threat Intelligence

Within hours of exposure, Anthropic’s Claude codebase moved from a controlled asset to an uncontrollable global artifact. Executive Summary A significant leak involving Anthropic’s Claude codebase triggered rapid dissemination across developer ecosystems, highlighting critical risks in software release…

Read More

Advanced cyber security analytics platform visualizing real-time threat intelligence, network vulnerabilities, and data breach prevention metrics on an interactive dashboard for proactive risk management and incident response