Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Dawson James Securities, Inc.

Dawson James Securities, Inc. Vendor Cyber Rating & Cyber Score

dawsonjames.com

Dawson James Securities specializes in capital raising for small and microcap public and private growth companies primarily in the Life Science/Health Care, Technology and Consumer sectors and is a full service investment banking firm with research, institutional and retail sales, as well as execution trading and corporate services. According to Sagient Research Systems*, Dawson James has been ranked as a top Placement Agent in terms of aggregate PIPE and RD transactions cumulatively since 2005. Dawson James utilizes a unique approach to financing using our "Diversified Investor Offering™" which blends investor interest using a combination of retail clients and institutional investors. Headquartered in Boca Raton, FL, Dawson James is


DJSI A.I CyberSecurity Scoring

DJSI
Company Information
Website:http://www.dawsonjames.com
Employees number:46
Number of followers:793
NAICS:52311
Industry Type:Investment Banking
Homepage:dawsonjames.com
DJSI Risk Score (AI oriented)
Between 650 and 699
logo
DJSIInvestment Banking
Updated:
07/03/2026
673/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DJSI Global Score (TPRM)
xxxx
logo
DJSIInvestment Banking
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DJSI
DJSIWeak
Current Score
673B (WEAK)
01000
3 incidents
-22 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
678Before Incident
MAY 2026
676Before Incident
APRIL 2026
676Before Incident
MARCH 2026
673Before Incident
FEBRUARY 2026
671Before Incident
JANUARY 2026
671Before Incident
DECEMBER 2025
690Before Incident
Cyber Attack
25 Dec 2025DJSI
AWS: TeamPCP Worm Exploits Cloud Infrastructure to Build Criminal Infrastructure

TeamPCP Launches Large-Scale Cloud-Native Cybercrime Campaign

668After Incident
CRITICAL-22
DAW1770631199
TeamPCP Launches Large-Scale Cloud-Native Cybercrime Campaign Cybersecurity researchers have uncovered a worm-driven campaign orchestrated by the threat group TeamPCP (also known as DeadCatx3, PCPcat, PersyPCP, and ShellForce), which has systematically targeted cloud-native environments to establish malicious infrastructure for follow-on exploitation. The operation, active since at least November 2025, was first observed around December 25, 2025, and leverages exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and the critical React2Shell vulnerability (CVE-2025-55182, CVSS 10.0). TeamPCP operates as a cloud-native cybercrime platform, exploiting misconfigurations and known vulnerabilities to breach modern cloud infrastructure. The group’s activities were first documented in December 2025 under Operation PCPcat, with its Telegram channel active since July 30, 2025 now hosting over 700 members and publishing stolen data from victims in Canada, Serbia, South Korea, the U.A.E., and the U.S. The campaign’s objectives include building a distributed proxy and scanning infrastructure, compromising servers for data exfiltration, ransomware deployment, extortion, and cryptocurrency mining. Rather than employing novel techniques, TeamPCP relies on automated, industrialized exploitation of well-known vulnerabilities and misconfigurations, transforming compromised infrastructure into a self-propagating criminal ecosystem. Key components of the attack include: - proxy.sh: Installs proxy, P2P, and tunneling utilities, along with scanners to identify vulnerable servers. It performs environment fingerprinting, branching into Kubernetes-specific execution paths if detected. - scanner.py: Scans for misconfigured Docker APIs and Ray dashboards using CIDR lists from a GitHub account (DeadCatx3), with options to deploy a cryptocurrency miner (mine.sh). - kube.py: Harvests Kubernetes cluster credentials, discovers resources, and propagates proxy.sh across pods while establishing persistent backdoors via privileged pods. - react.py: Exploits CVE-2025-29927 in React applications for remote command execution. - pcpcat.py: Automates the discovery of exposed Docker APIs and Ray dashboards, deploying malicious containers with Base64-encoded payloads. The campaign’s command-and-control (C2) server (67.217.57[.]240) has been linked to Sliver, an open-source C2 framework frequently abused by threat actors. Targets are primarily AWS and Microsoft Azure environments, with attacks being opportunistic rather than industry-specific, making organizations running such infrastructure collateral victims. TeamPCP’s hybrid monetization model combines infrastructure exploitation, data theft, and extortion, with stolen data including CV databases, identity records, and corporate files published via ShellForce to fuel ransomware, fraud, and cybercrime reputation-building. The group’s reliance on modified open-source tools and known vulnerabilities underscores its focus on scale and operational integration rather than technical innovation.
INCIDENT DETAILS -
TYPE
worm-driven campaigncybercrime platform
MOTIVATION
data exfiltrationransomware deploymentextortioncryptocurrency mininginfrastructure exploitation
IMPACT
CV databasesidentity recordscorporate filescloud-native environmentsAWS environmentsMicrosoft Azure environmentsOperational Impact: compromised infrastructure for follow-on exploitationIdentity Theft Risk: high
DATA BREACH
CV databasesidentity recordscorporate filesSensitivity Of Data: high
NOVEMBER 2025
689Before Incident
OCTOBER 2025
687Before Incident
SEPTEMBER 2025
686Before Incident
AUGUST 2025
685Before Incident
JULY 2025
683Before Incident
JUNE 2023
708Before Incident
Breach
29 Jun 2023DJSI
Dawson James Securities, Inc.

Unauthorized Access at Dawson James Securities, Inc.

639After Incident
MEDIUM-69
DAW607072725
The Maryland Office of the Attorney General reported that Dawson James Securities, Inc. experienced unauthorized access to its network between June 29, 2023, and June 30, 2023. The incident potentially affected personal information, including names, but the specific number of individuals impacted is not provided. The company has implemented security measures and is offering complimentary credit monitoring and identity protection services.
INCIDENT DETAILS -
TYPE
Unauthorized Access
IMPACT
names
DATA BREACH
Personal Informationnames
JANUARY 2021
746Before Incident
Breach
22 Jan 2021DJSI
Dawson James Securities, Inc.

Data Breach at Dawson James Securities, Inc.

673After Incident
MEDIUM-73
DAW845072925
The Pennsylvania Attorney General's Office reported a data breach involving Dawson James Securities, Inc. on March 1, 2021. The breach, which occurred on January 22, 2021, involved a missing computer that potentially exposed names, addresses, and social security numbers of individuals, affecting 558 Rhode Island residents.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesSocial Security Numbers
DATA BREACH
NamesAddressesSocial Security NumbersSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DJSI ?
?
What was DJSI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was DJSI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was DJSI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was DJSI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was DJSI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was DJSI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was DJSI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was DJSI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was DJSI's A.I Rankiteo Cyber Score in September 2025 ?
?
What was DJSI's A.I Rankiteo Cyber Score in August 2025 ?
?
What was DJSI's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on DJSI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DJSI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DJSI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Dawson James Securities, Inc. Cyber Scoring History | Rankiteo