Gurucul Gurucul is a security analytics company founded in data science that delivers radical clarity about cyber risk.

Gurucul is a leading provider of security, risk and threat intelligence solutions.

Recognition is not achieved overnight. It is built through innovation, customer trust, and a relentless commitment to so...
06/19/2026

Recognition is not achieved overnight. It is built through innovation, customer trust, and a relentless commitment to solving real security challenges.

We are proud to share Gurucul's journey from Visionary to Leader in the 2025 Gartner Magic Quadrant for SIEM.

Key highlights from our evolution:

🔹 Continuous innovation in security analytics and threat detection
🔹 A strong focus on delivering measurable customer outcomes
🔹 Advanced capabilities designed to help organizations stay ahead of evolving threats
🔹 A commitment to empowering security teams with greater visibility and efficiency

This milestone reflects the dedication of our team, the trust of our customers, and our vision for the future of cybersecurity.

As the security landscape continues to evolve, Gurucul remains focused on helping organizations strengthen resilience, accelerate response, and drive better security outcomes.

Read the full blog:
https://gurucul.com/blog/from-visionary-to-leader-guruculs-ascent-in-the-2025-gartner-magic-quadrant-for-siem/

What happens when a ransomware group's internal communications are exposed?A recent leak provided an unusually detailed ...
06/19/2026

What happens when a ransomware group's internal communications are exposed?

A recent leak provided an unusually detailed look into how the Gentlemen ransomware operation functions behind the scenes, revealing everything from affiliate recruitment and victim selection to credential abuse, data theft, extortion, and ransomware deployment.

Key insights from the research:

• More than 450 victims identified across 70+ countries
• Fortinet SSL VPN access repeatedly appeared in intrusion activity
• Stolen credentials and infostealer data played a major role in gaining access
• A structured Ransomware as a Service model offered affiliates up to 90% of ransom payments
• Internal communications exposed operational workflows, tooling, and monetization strategies
• Multiple detection opportunities were identified before encryption occurs

For defenders, the biggest takeaway is clear: the best opportunities to stop ransomware often exist during the early stages of an intrusion, long before encryption begins.

Read the full threat analysis and defensive recommendations.
https://gurucul.com/blog/threat-actor-profile-the-gentlemen/

Identity has become one of the most targeted attack surfaces in modern enterprises. As organizations continue to adopt c...
06/18/2026

Identity has become one of the most targeted attack surfaces in modern enterprises. As organizations continue to adopt cloud services, remote work models, and distributed identities, the challenge is no longer just managing access. It is detecting identity based threats before they become security incidents.

Identity Threat Detection and Response (ITDR) is emerging as a critical component of modern cybersecurity strategies, helping organizations identify compromised accounts, privilege misuse, and suspicious identity activity that traditional security controls may miss.

In this webinar, we explore:

• Key challenges organizations face in securing identities
• Best practices for strengthening identity security programs
• The growing role of advanced analytics in threat detection
• Why visibility into identity activity is essential for reducing risk

Learn how organizations are approaching identity security in an evolving threat landscape.
https://gurucul.com/resource/understanding-itdr-key-challenges-best-practices-and-the-role-of-advanced-analytics/

Security operations teams are facing an increasingly difficult challenge: more data, more alerts, and more sophisticated...
06/17/2026

Security operations teams are facing an increasingly difficult challenge: more data, more alerts, and more sophisticated threats, all while expectations for faster response continue to rise. Traditional approaches often leave analysts spending valuable time correlating information across multiple systems rather than focusing on high priority risks.

Gurucul Next Gen SIEM helps organizations modernize security operations by providing:
• Unified visibility across security data sources
• Faster threat detection and investigation workflows
• Advanced analytics to uncover meaningful risks
• Improved operational efficiency for security teams

By bringing together critical security telemetry and actionable intelligence, organizations can strengthen threat detection capabilities, reduce investigation time, and improve overall security effectiveness.

As cyber threats continue to evolve, security leaders need a modern approach that delivers both visibility and operational agility. Gurucul Next Gen SIEM helps security teams focus on what matters most: identifying, investigating, and responding to threats with confidence.

Learn how Gurucul Next Gen SIEM is helping organizations modernize security operations.
https://gurucul.com/products/next-gen-siem/

🚨 Trusted software dependencies are becoming a preferred attack vector for cybercriminals.Researchers uncovered a campai...
06/10/2026

🚨 Trusted software dependencies are becoming a preferred attack vector for cybercriminals.

Researchers uncovered a campaign in which TeamPCP allegedly compromised Microsoft's DurableTask package on PyPI to distribute credential theft malware. By leveraging a trusted package repository, the attackers sought to harvest developer credentials, cloud secrets, API tokens, and CI CD access that could enable broader compromise across enterprise environments.

🔹 Exposure of developer and cloud credentials
🔹 Increased risk of unauthorized infrastructure access
🔹 Potential downstream supply chain impact
🔹 Greater risk across CI CD and development environments

Why this matters:

A single compromised dependency can expose organizations to credential theft, operational disruption, and broader security risks across connected systems and services.

✅ Monitor software dependencies continuously
✅ Enforce least privilege access controls
✅ Strengthen identity and secrets management
✅ Enhance visibility across developer environments
✅ Test incident response readiness regularly

Read the full analysis to understand the risks, indicators, and recommended defenses.

https://gurucul.com/blog/teampcp-compromises-microsofts-durabletask-pypi-package-to-deploy-multi-stage-credential-theft-malware/

🏥 Healthcare remains one of the most targeted sectors for ransomware attacks.Gurucul Threat Intelligence has analyzed th...
06/03/2026

🏥 Healthcare remains one of the most targeted sectors for ransomware attacks.

Gurucul Threat Intelligence has analyzed the alleged Qilin ransomware attack targeting CLINICA AVELLANEDA MEDICAL CENTER, where threat actors claim to have exfiltrated sensitive patient information and medical records.

Key concerns include:
🔹 Exposure of patient PII and healthcare data
🔹 Potential medical identity theft and insurance fraud
🔹 Increased phishing and social engineering risks
🔹 Operational and regulatory challenges for healthcare providers

As ransomware groups continue to leverage double-extortion tactics, proactive threat detection, strong access controls, and continuous monitoring have become critical for protecting healthcare organizations.

Read the full analysis to understand the risks and recommended defenses.
https://tinyurl.com/2wfv7kwb

🚨 2,800+ GitHub files. One massive supply chain threat.Gurucul Threat Research Labs has uncovered details of the Megalod...
06/02/2026

🚨 2,800+ GitHub files. One massive supply chain threat.

Gurucul Threat Research Labs has uncovered details of the Megalodon malware campaign, which abused GitHub Actions workflows to steal sensitive credentials from CI/CD environments at scale.

The attack targeted:
🔹 GitHub tokens
🔹 AWS credentials
🔹 API keys
🔹 Database secrets
🔹 SSH keys

By embedding obfuscated payloads into trusted workflows, attackers were able to harvest secrets and communicate with external infrastructure—highlighting the growing risk of software supply chain compromises.

Read the full research to understand the attack chain, indicators of compromise, and detection opportunities.
https://tinyurl.com/3jt6xpdw

🚨 Threat actors are evolving—and so are their tactics.Gurucul Threat Research Labs has uncovered a sophisticated ClickFi...
06/01/2026

🚨 Threat actors are evolving—and so are their tactics.

Gurucul Threat Research Labs has uncovered a sophisticated ClickFix campaign leveraging Donut shellcode and fileless ex*****on techniques to deploy the PureLogs stealer.

The attack uses social engineering, in-memory payload ex*****on, and behavioral evasion techniques to steal credentials, browser data, cryptocurrency wallets, and sensitive enterprise information.

Key findings:
🔹 ClickFix-based social engineering
🔹 Fileless PowerShell and Donut shellcode ex*****on
🔹 Credential and cryptocurrency wallet theft
🔹 In-memory .NET payload deployment
🔹 Advanced C2 communications

Read the full analysis and learn how to detect and defend against this evolving threat landscape.
https://gurucul.com/blog/canndelta-clickfix-campaign-abusing-donut-shellcode-to-deploy-purelogs-stealer/

Trusted package.Hidden payload.Developer environments at risk.Software supply chain attacks are evolving—and now increas...
05/21/2026

Trusted package.
Hidden payload.
Developer environments at risk.

Software supply chain attacks are evolving—and now increasingly targeting the AI ecosystem itself.

A malicious version of the widely used Guardrails-AI PyPI package (v0.10.1) was found containing injected code that automatically downloaded and executed a remote payload during package import.

What makes this attack concerning:

• Malicious code embedded directly into __init__.py
• Ex*****on triggered automatically on import
• Remote payload download and ex*****on
• Potential exposure of API keys, cloud credentials, and development secrets
• Impact across AI development pipelines and enterprise environments

The larger takeaway:

Attackers are no longer just targeting applications.
👉 They're targeting the tools developers trust to build them.

Security teams should prioritize:
✅ Dependency governance and validation
✅ CI/CD security controls
✅ Package integrity monitoring
✅ Behavioral detection for suspicious ex*****on patterns

Because in modern environments, a package update can become an attack path.

Address

222 North Pacific Coast Highway, Suite 1322
El Segundo, CA
90245

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm

Alerts

Be the first to know and let us send you an email when Gurucul posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Gurucul:

Share