CloudSEK is a contextual AI company that predicts Cyber Threats.
Combining the power of Cyber,Brand & Attack Surface monitoring to give context to Digital Risk
A legitimate npm package was compromised — and the malicious release still carried valid provenance. CloudSEK uncovered GHAPPIER, spanning 65 repositories, 73 infected files and 22 accounts.
Full research: cloudsek.com/blog/ghappier-m…
A routine npm install can cross from WSL into Windows.
CloudSEK’s BRIDGEHEAD investigation found 40 typosquatted npm packages delivering a payload targeting crypto wallets, browser credentials and Telegram sessions.
Read: cloudsek.com/blog/bridgehead…
CloudSEK uncovered an exposed attacker workspace with 142K+ files, revealing AI agents being used to automate offensive hacking. Evidence includes 8,996 compromised WordPress sites, stolen credentials and crypto wallet data.
cloudsek.com/blog/ai-agent-d…
2,500+ organisations potentially exposed in a major AI supply-chain breach involving LiteLLM. Cloud credentials, source-code access and AI/API keys may be at risk — with stolen access potentially reusable even months later.
Report: cloudsek.com/blog/ai-supply-…
France-linked underground cyber activity has surged more than 4X in two years. What is driving the rise, and which sectors face the greatest risk?Explore CloudSEK’s latest threat report:
cloudsek.com/blog/france-dar…
CloudSEK has partnered with Tech Mahindra to deliver AI-driven threat intelligence, attack surface monitoring, and digital risk protection — helping enterprises spot risks earlier, respond faster, and stay regulation-ready.
cloudsek.com/ancmt/cloudsek-…
Business phone systems are under attack. CloudSEK recorded 1.86M credential attempts and nearly 90,000 suspected toll-fraud calls in 18 days, exposing 277,632 attacker-used passwords.
cloudsek.com/blog/the-5060-s…
FortiBleed: Hype vs Reality
Claims say 21k+ domains breached, but CloudSEK found the truth:
❌ Not a zero-day, just brute-forcing
📉 Only 148 actually compromised
🛡️ Secure your admin interfaces
Full analysis & IoCs: cloudsek.com/blog/inside-the…
Phishing is moving beyond stolen passwords.
CloudSEK uncovered BlueKit, a PhaaS platform with 87 phishing kits, session theft, automated account takeover and P2P infrastructure built to evade detection.
Read the report: cloudsek.com/blog/bluekit-ph…
An exposed attacker server revealed the machinery behind Operation Escaneo—a cyber campaign targeting government, financial and critical infrastructure across Mexico and LATAM.
CloudSEK maps the tools, exploits and data theft.
cloudsek.com/blog/operation-…
Fake tickets. Stolen cards. OTP bypass.
CloudSEK uncovered a Chinese-origin FIFA World Cup 2026 fraud network using cloned ticket sites, live victim tracking and payment interception.
Could you spot the fake?
cloudsek.com/blog/chinese-or…
IPL betting scams are going high-tech.
CloudSEK found 1,200+ illegal betting domains, AI deepfake promos, mule accounts, compromised govt sites, fake loan apps and ₹4.65 crore in rejected withdrawals from one backend alone.
Read: cloudsek.com/blog/illegal-ip…
IPL fever is turning into scam season.
CloudSEK found 600+ fake IPL ticketing domains and 400+ fake streaming sites targeting fans with fake QR tickets, payment traps and malware built to steal passwords, browser data and crypto wallets.
Read: cloudsek.com/blog/hit-wicket…
New supply chain threat uncovered
CloudSEK TRIAD found an npm campaign using crypto-javascri, a typosquatted package impersonating crypto-js.
It steals npm/GitHub credentials, hijacks maintainer accounts, and uses Tor-based C2 to stay harder to disrupt.
cloudsek.com/blog/inside-a-t…
What if the cyber reconnaissance came before the missiles? CloudSEK’s latest report explores alleged APT35 activity across GCC targets, from aviation to energy, and why defenders should pay close attention to the region’s cyber risk now.
cloudsek.com/blog/kitten-had…
What developers thought was harmless is now access to AI.
CloudSEK found 32 hardcoded Google API keys across 22 Android apps — used by 500M+ users — now exposing access to Gemini AI.
No warning. Just risk.
cloudsek.com/blog/hardcoded-…
That “free gift” link isn’t random. It’s engineered.
CloudSEK exposes a global network abusing 300+ brands to profile users and funnel them into scams.
Phishing is now targeted, scalable, and industrial.
Read: cloudsek.com/blog/large-scal…
CloudSEK Triad has published a detailed investigation into the RAMP cybercrime forum, covering its operations and working from 2021 through its seizure by the FBI in January 2026.
Read the full report: cloudsek.com/blog/the-rise-a…
Attackers don’t need to build AI anymore. They just need to break it.
This report shows how AI pipelines, not models, are becoming the weakest link in modern cyber conflict.
Dive in: cloudsek.com/blog/ai-infrast…
Iran–US escalation is pushing cyber risk into critical infrastructure.
CloudSEK’s new report maps ICS/OT threat actors and shows why disruption may not need advanced exploits.
In many cases, internet exposure + weak/default access is enough.
cloudsek.com/blog/a-threat-a…