Blog

Featured SOC Security Analytics

From Visionary to Leader: Gurucul’s Ascent in the 2025 Gartner Magic Quadrant for SIEM

We’re thrilled to announce that Gurucul has been recognized as a Leader in the 2025 Gartner Magic Quadrant for Security Information and Event Management (SIEM). After three consecutive…

April 1, 2026

Crypto Drainers: From Wallet Approval Abuse to Malware-Assisted Web3 Attacks

Threat Research

Introduction Crypto drainers represent a class of financially motivated threats targeting Web3 users by abusing blockchain transaction authorization mechanisms rather than exploiting software vulnerabilities. Instead of stealing credentials or deploying traditional malware, these attacks manipulate…

Read More

March 30, 2026

The 11- Minute Heist: Why Traditional Security Fails to Catch the “Ghost” in Your Network

Threat Intelligence

Introduction Modern Security Operations Centers (SOCs) are currently facing a paradox: they have more data than ever before, yet they have never been more blind. Analysts are drowning in thousands of daily alerts, most of which lack the context…

Read More

March 26, 2026

SURXRAT: MaaS Android RAT Leveraging Telegram and Firebase Infrastructure

Threat Research

Executive Summary SURXRAT is an Android-based Remote Access Trojan (RAT) operating under a Malware-as-a-Service (MaaS) model and distributed primarily through Telegram channels. The malware provides operators with full remote control over infected devices, enabling surveillance, data exfiltration, and device…

Read More

March 24, 2026

Pinnacle Tax Inc Data Leak

Threat Intelligence

Executive Summary On March 16, 2026, the ransomware group Qilin Ransomware publicly claimed responsibility for a cyberattack targeting Pinnacle Tax Inc., a U.S.-based provider of tax planning and financial services. If confirmed, this incident represents a high-impact data breach…

Read More

March 20, 2026

The Machine is Now the Insider: Critical Takeaways from the 2026 Insider Risk Report

Insider Threat

For years, the “insider threat” was a Hollywood trope: the disgruntled spy walking out with a briefcase of trade secrets. According to the 2026 Insider Risk Report, that era is fading. Today, insider risk isn’t an occasional…

Read More

March 17, 2026

Detecting Oblivion Android RAT: Accessibility Abuse, OTP Interception, and Mobile Threat Behavior

Threat Research

Overview Oblivion is an Android Remote Access Trojan (RAT) advertised on underground forums as a comprehensive mobile surveillance and fraud toolkit. The malware is promoted with capabilities ranging from remote device interaction to credential theft and persistent access.

Read More

March 11, 2026

Mapping Hacktivist Cyber Operations in the Iran–Israel–US Geopolitical Conflict

Threat Intelligence

Executive Summary The escalation of geopolitical tensions involving Iran, Israel, and the United States has been accompanied by a surge in hacktivist cyber operations targeting government institutions, financial platforms, infrastructure organizations, and private companies across multiple regions.

Read More

March 6, 2026

Cyber Fallout from the Iran–Israel–US Conflict: Monitoring Emerging Nation-State Cyber Threat Activity

Threat Research

Introduction Modern geopolitical conflicts increasingly extend beyond traditional battlefields into the cyber domain. Nation-state actors now routinely leverage cyber operations to conduct espionage, disrupt infrastructure, and retaliate against adversaries. The current geopolitical tensions involving Iran…

Read More

March 3, 2026

Envirogen Technologies Allegedly Targeted by Anubis Ransomware

Threat Intelligence

Executive Summary : Envirogen Technologies, Inc. has reportedly become the latest victim of a large-scale ransomware attack. The ransomware group Anubis has claimed responsibility, alleging the exfiltration of approximately 3.6 terabytes of data comprising over three million…

Read More

February 27, 2026

Data Leak – Substack Confirms Security Incident

Threat Intelligence

Executive Summary Substack, a subscription-based publishing platform, suffered a data breach that occurred in October 2025 and was discovered on February 3, 2026, during which an unauthorized party accessed and later leaked user account data affecting overall 697,298 users;…

Read More

February 26, 2026

Fit-Line Global Data Leak

Threat Intelligence

Executive Summary On January 9, 2026, the ransomware group INC Ransom publicly claimed responsibility for a cyberattack against Fit-Line Global, a manufacturing-sector organization. The group alleges exfiltration of sensitive corporate and employee data, including personal…

Read More

February 25, 2026

Beyond the Schema: How Gurucul Powers OCSF

Introduction Security teams today face a constant balancing act. They must rapidly onboard new telemetry sources while also ensuring consistency for correlation, investigation, and reporting. Flexibility and standardization often collide, creating friction across tools and teams.

Read More

Advanced cyber security analytics platform visualizing real-time threat intelligence, network vulnerabilities, and data breach prevention metrics on an interactive dashboard for proactive risk management and incident response