Gurucul
Gurucul is a security analytics company founded in data science that delivers radical clarity about cyber risk.
Gurucul is a leading provider of security, risk and threat intelligence solutions.
06/03/2026
๐ฅ Healthcare remains one of the most targeted sectors for ransomware attacks.
Gurucul Threat Intelligence has analyzed the alleged Qilin ransomware attack targeting CLINICA AVELLANEDA MEDICAL CENTER, where threat actors claim to have exfiltrated sensitive patient information and medical records.
Key concerns include:
๐น Exposure of patient PII and healthcare data
๐น Potential medical identity theft and insurance fraud
๐น Increased phishing and social engineering risks
๐น Operational and regulatory challenges for healthcare providers
As ransomware groups continue to leverage double-extortion tactics, proactive threat detection, strong access controls, and continuous monitoring have become critical for protecting healthcare organizations.
Read the full analysis to understand the risks and recommended defenses.
https://tinyurl.com/2wfv7kwb
06/02/2026
๐จ 2,800+ GitHub files. One massive supply chain threat.
Gurucul Threat Research Labs has uncovered details of the Megalodon malware campaign, which abused GitHub Actions workflows to steal sensitive credentials from CI/CD environments at scale.
The attack targeted:
๐น GitHub tokens
๐น AWS credentials
๐น API keys
๐น Database secrets
๐น SSH keys
By embedding obfuscated payloads into trusted workflows, attackers were able to harvest secrets and communicate with external infrastructureโhighlighting the growing risk of software supply chain compromises.
Read the full research to understand the attack chain, indicators of compromise, and detection opportunities.
https://tinyurl.com/3jt6xpdw
06/01/2026
๐จ Threat actors are evolvingโand so are their tactics.
Gurucul Threat Research Labs has uncovered a sophisticated ClickFix campaign leveraging Donut shellcode and fileless ex*****on techniques to deploy the PureLogs stealer.
The attack uses social engineering, in-memory payload ex*****on, and behavioral evasion techniques to steal credentials, browser data, cryptocurrency wallets, and sensitive enterprise information.
Key findings:
๐น ClickFix-based social engineering
๐น Fileless PowerShell and Donut shellcode ex*****on
๐น Credential and cryptocurrency wallet theft
๐น In-memory .NET payload deployment
๐น Advanced C2 communications
Read the full analysis and learn how to detect and defend against this evolving threat landscape.
https://gurucul.com/blog/canndelta-clickfix-campaign-abusing-donut-shellcode-to-deploy-purelogs-stealer/
05/21/2026
Trusted package.
Hidden payload.
Developer environments at risk.
Software supply chain attacks are evolvingโand now increasingly targeting the AI ecosystem itself.
A malicious version of the widely used Guardrails-AI PyPI package (v0.10.1) was found containing injected code that automatically downloaded and executed a remote payload during package import.
What makes this attack concerning:
โข Malicious code embedded directly into __init__.py
โข Ex*****on triggered automatically on import
โข Remote payload download and ex*****on
โข Potential exposure of API keys, cloud credentials, and development secrets
โข Impact across AI development pipelines and enterprise environments
The larger takeaway:
Attackers are no longer just targeting applications.
๐ They're targeting the tools developers trust to build them.
Security teams should prioritize:
โ
Dependency governance and validation
โ
CI/CD security controls
โ
Package integrity monitoring
โ
Behavioral detection for suspicious ex*****on patterns
Because in modern environments, a package update can become an attack path.
05/21/2026
No exploit. No vulnerability.
Just one click and one command.
Attackers are increasingly moving away from complex exploit chains and relying on something much simpler: human trust.
This latest campaign abused fake Google Meet verification pages to trick users into running an obfuscated PowerShell command, ultimately delivering SalatStealer, an information-stealing malware designed to target browser credentials, session cookies, and cryptocurrency wallets.
What makes this attack effective:
โข ClickFix-style social engineering
โข Abuse of legitimate Windows tools like PowerShell and BITSAdmin
โข Memory-based payload staging
โข Browser credential and cookie theft
โข Cryptocurrency wallet targeting across multiple platforms
The bigger takeaway:
Attackers don't always need sophisticated exploits anymore.
๐ Sometimes all they need is user interaction and legitimate tools already present in the environment.
Detection teams should prioritize:
โ
Hidden PowerShell ex*****on patterns
โ
LOLBin abuse activity
โ
Abnormal browser data access
โ
Suspicious process ex*****on from user directories
Modern threats increasingly blend into normal activity.
The challenge isn't just detecting malware.
It's detecting behavior.
https://tinyurl.com/mv46t7f9
05/18/2026
๐๐ฟ๐ผ๐บ ๐-๐๐๐ ๐๐ผ ๐๐ต๐ฒ ๐๐๐ฟ๐๐ฐ๐๐น ๐๐๐ฏ๐ฒ๐ฟ ๐๐ฟ๐ผ๐ป๐๐น๐ถ๐ป๐ฒ๐.
๐ ๐ป๐ฒ๐ ๐ฐ๐ต๐ฎ๐ฝ๐๐ฒ๐ฟ ๐ฏ๐ฒ๐ด๐ถ๐ป๐.
We are excited to welcome these talented young engineers from C-DAC Pune to Gurucul as they begin their professional journey into AI-driven cybersecurity, intelligent threat detection, and modern SOC operations.
What makes this generation exciting is not just technical knowledge but the curiosity, adaptability, and systems-thinking mindset they bring from day one.
At Gurucul, they now transition:
โข From learning โ to securing
โข From theory โ to defending enterprises
โข From campus projects โ to building AI-driven cyber defense platforms
The future of cybersecurity will belong to engineers who can combine AI, automation, analytical thinking, and human intelligence to solve increasingly complex security challenges.
This is more than onboarding.
It is the beginning of a meaningful mission.
Welcome to Gurucul. Welcome to the cyber frontlines.
05/15/2026
Insider risk involves individuals with legitimate access, making detection more complex than external threats.
Gurucul AI-Powered Insider Risk Management continuously evaluates user behavior, access patterns, and risk signals to identify potential threats.
By building comprehensive risk profiles, it enables organizations to detect early signs of misuse and take preventive action.
Key capabilities include:
โข Continuous monitoring of user activity
โข Behavioral analysis for anomaly detection
โข Risk scoring for prioritization
โข Early identification of potential data risks
This supports proactive management of insider threats with data-driven insights.
Learn more: https://gurucul.com/products/ai-powered-insider-risk-management/
05/14/2026
Not every exposure starts with a breach.
Sometimes, it starts with public data at scale.
The alleged Polymarket exposure highlights a growing cybersecurity challenge in decentralized ecosystems:
๐ Large-scale aggregation of publicly accessible metadata.
According to claims made by the threat actor XORCAT:
โข Over 10 million records were allegedly aggregated
โข Around 300,000 user-associated identities may have been exposed
โข Public APIs and blockchain-linked metadata were leveraged for collection
Polymarket stated that no internal compromise occurred and that the information was already publicly accessible.
But thatโs the real lesson.
Even without a traditional breach:
โ Public APIs can enable large-scale reconnaissance
โ Wallet attribution can lead to deanonymization
โ Metadata correlation can fuel phishing, profiling, and future attacks
This incident reinforces why organizations must treat:
โข API security
โข Behavioral monitoring
โข Metadata minimization
โข Automated scraping detection
โฆas critical parts of modern cyber defense.
Because in todayโs threat landscape,
๐ exposed metadata can become actionable intelligence.
https://tinyurl.com/uwz96x4v
05/14/2026
Many advanced threats operate within legitimate access, making them difficult to detect using traditional rule-based systems.
Gurucul User and Entity Behavior Analytics (UEBA) focuses on understanding how users, devices, and systems behave over time.
By establishing baselines for normal activity, it identifies deviations that may indicate compromised credentials or insider misuse. These signals are combined to create a risk profile for each entity.
Key capabilities include:
โข Continuous monitoring of user and system behavior
โข Detection of subtle anomalies
โข Risk scoring based on aggregated signals
โข Integration with investigation workflows
This enables early detection of threats that may otherwise remain unnoticed.
Learn more: https://gurucul.com/products/user-and-entity-behavior-analytics-ueba/
Click here to claim your Sponsored Listing.
Category
Contact the business
Website
Address
222 North Pacific Coast Highway, Suite 1322
El Segundo, CA
90245
Opening Hours
| Monday | 8am - 6pm |
| Tuesday | 8am - 6pm |
| Wednesday | 8am - 6pm |
| Thursday | 8am - 6pm |
| Friday | 8am - 6pm |