Skip to content

company

CloudSEK

CloudSEK is a cybersecurity threat intelligence company that tracks data breaches, supply chain attacks, and digital risks for enterprises.

Known aliases

  • cloudsek.com
  • CloudSEK TRIAD

Relationships

No evidence-backed relationships are recorded.

Current stories

security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62
security4 publishers

Aurora operators drove Cursor Agent through ten victim networks over six weeks

Gambit Security says the ransomware crew used a commercial coding agent for hands-on post-compromise work between 8 April and 21 May, alongside a new Linux encryptor that force-kills running guests before it touches ESXi datastores.

Publishers:gambit.securityinfosecurity-magazine.comscworld.comthehackernews.com

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence78
Adoption60
Hype gap+22
Incentives58
Confidence70
security3 publishers

BigBear's phishing panel disables WebAuthn in the browser to beat MFA at 258 organizations

CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence55
Adoption30
Hype gap+25
Incentives40
Confidence60
security7 publishers

Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token

CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.

Publishers:crowdsec.netgithub.cominfosecurity-magazine.comold.tanstack.comorca.securitysecurityweek.comthehackernews.com

Perspective Coverage

7 publishers
Builder
Builder 39%
Operator
Operator 52%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives65
Confidence60