Gurucul

Gurucul

Share

Gurucul is a security analytics company founded in data science that delivers radical clarity about cyber risk.

Gurucul is a leading provider of security, risk and threat intelligence solutions.

06/03/2026

๐Ÿฅ Healthcare remains one of the most targeted sectors for ransomware attacks.

Gurucul Threat Intelligence has analyzed the alleged Qilin ransomware attack targeting CLINICA AVELLANEDA MEDICAL CENTER, where threat actors claim to have exfiltrated sensitive patient information and medical records.

Key concerns include:
๐Ÿ”น Exposure of patient PII and healthcare data
๐Ÿ”น Potential medical identity theft and insurance fraud
๐Ÿ”น Increased phishing and social engineering risks
๐Ÿ”น Operational and regulatory challenges for healthcare providers

As ransomware groups continue to leverage double-extortion tactics, proactive threat detection, strong access controls, and continuous monitoring have become critical for protecting healthcare organizations.

Read the full analysis to understand the risks and recommended defenses.
https://tinyurl.com/2wfv7kwb

06/02/2026

๐Ÿšจ 2,800+ GitHub files. One massive supply chain threat.

Gurucul Threat Research Labs has uncovered details of the Megalodon malware campaign, which abused GitHub Actions workflows to steal sensitive credentials from CI/CD environments at scale.

The attack targeted:
๐Ÿ”น GitHub tokens
๐Ÿ”น AWS credentials
๐Ÿ”น API keys
๐Ÿ”น Database secrets
๐Ÿ”น SSH keys

By embedding obfuscated payloads into trusted workflows, attackers were able to harvest secrets and communicate with external infrastructureโ€”highlighting the growing risk of software supply chain compromises.

Read the full research to understand the attack chain, indicators of compromise, and detection opportunities.
https://tinyurl.com/3jt6xpdw

06/01/2026

๐Ÿšจ Threat actors are evolvingโ€”and so are their tactics.

Gurucul Threat Research Labs has uncovered a sophisticated ClickFix campaign leveraging Donut shellcode and fileless ex*****on techniques to deploy the PureLogs stealer.

The attack uses social engineering, in-memory payload ex*****on, and behavioral evasion techniques to steal credentials, browser data, cryptocurrency wallets, and sensitive enterprise information.

Key findings:
๐Ÿ”น ClickFix-based social engineering
๐Ÿ”น Fileless PowerShell and Donut shellcode ex*****on
๐Ÿ”น Credential and cryptocurrency wallet theft
๐Ÿ”น In-memory .NET payload deployment
๐Ÿ”น Advanced C2 communications

Read the full analysis and learn how to detect and defend against this evolving threat landscape.
https://gurucul.com/blog/canndelta-clickfix-campaign-abusing-donut-shellcode-to-deploy-purelogs-stealer/

05/21/2026

Trusted package.
Hidden payload.
Developer environments at risk.

Software supply chain attacks are evolvingโ€”and now increasingly targeting the AI ecosystem itself.

A malicious version of the widely used Guardrails-AI PyPI package (v0.10.1) was found containing injected code that automatically downloaded and executed a remote payload during package import.

What makes this attack concerning:

โ€ข Malicious code embedded directly into __init__.py
โ€ข Ex*****on triggered automatically on import
โ€ข Remote payload download and ex*****on
โ€ข Potential exposure of API keys, cloud credentials, and development secrets
โ€ข Impact across AI development pipelines and enterprise environments

The larger takeaway:

Attackers are no longer just targeting applications.
๐Ÿ‘‰ They're targeting the tools developers trust to build them.

Security teams should prioritize:
โœ… Dependency governance and validation
โœ… CI/CD security controls
โœ… Package integrity monitoring
โœ… Behavioral detection for suspicious ex*****on patterns

Because in modern environments, a package update can become an attack path.

05/21/2026

No exploit. No vulnerability.
Just one click and one command.

Attackers are increasingly moving away from complex exploit chains and relying on something much simpler: human trust.

This latest campaign abused fake Google Meet verification pages to trick users into running an obfuscated PowerShell command, ultimately delivering SalatStealer, an information-stealing malware designed to target browser credentials, session cookies, and cryptocurrency wallets.

What makes this attack effective:
โ€ข ClickFix-style social engineering
โ€ข Abuse of legitimate Windows tools like PowerShell and BITSAdmin
โ€ข Memory-based payload staging
โ€ข Browser credential and cookie theft
โ€ข Cryptocurrency wallet targeting across multiple platforms

The bigger takeaway:

Attackers don't always need sophisticated exploits anymore.
๐Ÿ‘‰ Sometimes all they need is user interaction and legitimate tools already present in the environment.

Detection teams should prioritize:
โœ… Hidden PowerShell ex*****on patterns
โœ… LOLBin abuse activity
โœ… Abnormal browser data access
โœ… Suspicious process ex*****on from user directories

Modern threats increasingly blend into normal activity.
The challenge isn't just detecting malware.
It's detecting behavior.
https://tinyurl.com/mv46t7f9

05/18/2026

๐—™๐—ฟ๐—ผ๐—บ ๐—–-๐——๐—”๐—– ๐˜๐—ผ ๐˜๐—ต๐—ฒ ๐—š๐˜‚๐—ฟ๐˜‚๐—ฐ๐˜‚๐—น ๐—–๐˜†๐—ฏ๐—ฒ๐—ฟ ๐—™๐—ฟ๐—ผ๐—ป๐˜๐—น๐—ถ๐—ป๐—ฒ๐˜€.
๐—” ๐—ป๐—ฒ๐˜„ ๐—ฐ๐—ต๐—ฎ๐—ฝ๐˜๐—ฒ๐—ฟ ๐—ฏ๐—ฒ๐—ด๐—ถ๐—ป๐˜€.

We are excited to welcome these talented young engineers from C-DAC Pune to Gurucul as they begin their professional journey into AI-driven cybersecurity, intelligent threat detection, and modern SOC operations.

What makes this generation exciting is not just technical knowledge but the curiosity, adaptability, and systems-thinking mindset they bring from day one.

At Gurucul, they now transition:
โ€ข From learning โ†’ to securing
โ€ข From theory โ†’ to defending enterprises
โ€ข From campus projects โ†’ to building AI-driven cyber defense platforms

The future of cybersecurity will belong to engineers who can combine AI, automation, analytical thinking, and human intelligence to solve increasingly complex security challenges.

This is more than onboarding.
It is the beginning of a meaningful mission.

Welcome to Gurucul. Welcome to the cyber frontlines.

05/15/2026

Insider risk involves individuals with legitimate access, making detection more complex than external threats.

Gurucul AI-Powered Insider Risk Management continuously evaluates user behavior, access patterns, and risk signals to identify potential threats.

By building comprehensive risk profiles, it enables organizations to detect early signs of misuse and take preventive action.

Key capabilities include:
โ€ข Continuous monitoring of user activity
โ€ข Behavioral analysis for anomaly detection
โ€ข Risk scoring for prioritization
โ€ข Early identification of potential data risks
This supports proactive management of insider threats with data-driven insights.

Learn more: https://gurucul.com/products/ai-powered-insider-risk-management/

05/14/2026

Not every exposure starts with a breach.
Sometimes, it starts with public data at scale.

The alleged Polymarket exposure highlights a growing cybersecurity challenge in decentralized ecosystems:
๐Ÿ‘‰ Large-scale aggregation of publicly accessible metadata.

According to claims made by the threat actor XORCAT:
โ€ข Over 10 million records were allegedly aggregated
โ€ข Around 300,000 user-associated identities may have been exposed
โ€ข Public APIs and blockchain-linked metadata were leveraged for collection

Polymarket stated that no internal compromise occurred and that the information was already publicly accessible.

But thatโ€™s the real lesson.

Even without a traditional breach:
โš  Public APIs can enable large-scale reconnaissance
โš  Wallet attribution can lead to deanonymization
โš  Metadata correlation can fuel phishing, profiling, and future attacks

This incident reinforces why organizations must treat:
โ€ข API security
โ€ข Behavioral monitoring
โ€ข Metadata minimization
โ€ข Automated scraping detection

โ€ฆas critical parts of modern cyber defense.

Because in todayโ€™s threat landscape,
๐Ÿ‘‰ exposed metadata can become actionable intelligence.
https://tinyurl.com/uwz96x4v

05/14/2026

Many advanced threats operate within legitimate access, making them difficult to detect using traditional rule-based systems.

Gurucul User and Entity Behavior Analytics (UEBA) focuses on understanding how users, devices, and systems behave over time.

By establishing baselines for normal activity, it identifies deviations that may indicate compromised credentials or insider misuse. These signals are combined to create a risk profile for each entity.

Key capabilities include:
โ€ข Continuous monitoring of user and system behavior
โ€ข Detection of subtle anomalies
โ€ข Risk scoring based on aggregated signals
โ€ข Integration with investigation workflows
This enables early detection of threats that may otherwise remain unnoticed.

Learn more: https://gurucul.com/products/user-and-entity-behavior-analytics-ueba/

Want your business to be the top-listed Computer & Electronics Service in El Segundo?
Click here to claim your Sponsored Listing.

Address


222 North Pacific Coast Highway, Suite 1322
El Segundo, CA
90245

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm