Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Vendrive

Vendrive Vendor Cyber Rating & Cyber Score

goaura.com

A better way to price your products.


Vendrive A.I CyberSecurity Scoring

Vendrive
Company Information
Website:https://goaura.com/
Employees number:7
Number of followers:663
NAICS:5112
Industry Type:Software Development
Homepage:goaura.com
Vendrive Risk Score (AI oriented)
Between 0 and 549
logo
VendriveSoftware Development
Updated:
01/04/2026
541/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Vendrive Global Score (TPRM)
xxxx
logo
VendriveSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

VendriveCritical
Current Score
541C (CRITICAL)
01000
3 incidents
-70.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
562Before Incident
AUGUST 2026
558Before Incident
JULY 2026
555Before Incident
JUNE 2026
552Before Incident
MAY 2026
549Before Incident
APRIL 2026
547Before Incident
Vulnerability
01 Apr 2026 • Vendrive
Trivy, Cisco, Salesforce, AWS and Aura: Cisco Faces Alleged Data Leak as ShinyHunters Claims Responsibility

Cisco Hit by Major Cyberattack Linked to Supply Chain Breach

541After Incident
CRITICAL-6
AQUUSEAMASALCIS1775046662
Cisco Hit by Major Cyberattack Linked to Supply Chain Breach Cisco is responding to a significant cybersecurity incident after threat actors breached its internal development networks, stealing sensitive source code and corporate data. The attack, claimed by the hacking group ShinyHunters, also allegedly impacted Salesforce, Aura, and AWS storage buckets. The breach originated from a supply chain attack involving Trivy, a widely used vulnerability scanner. Attackers exploited a malicious GitHub Action plugin tied to the Trivy compromise, allowing them to steal credentials and infiltrate Cisco’s build environments. Once inside, they compromised dozens of devices, including lab workstations and developer systems, gaining access to highly sensitive data. The stolen material includes AWS keys, which were used to perform unauthorized actions in Cisco’s cloud accounts, and over 300 private GitHub repositories. These repositories contain unreleased product source code, including AI Assistants and AI Defense technologies, as well as data belonging to corporate clients, such as major banks, BPO firms, and U.S. government agencies. Cisco’s security teams including the Unified Intelligence Center, CSIRT, and EOC moved quickly to contain the breach by isolating affected systems, wiping compromised machines, and enforcing a mass credential reset. However, the company has not yet issued a public statement, and internal sources suggest ongoing complications from the incident. While ShinyHunters has taken credit for the data theft, security researchers link the underlying Trivy supply chain attack to TeamPCP, a separate group known for deploying custom malware ("TeamPCP Cloud Stealer") to hijack developer platforms like Docker, NPM, and PyPi. TeamPCP has also been tied to recent breaches of LiteLLM and Checkmarx, raising concerns about secondary attacks stemming from related vulnerabilities.
INCIDENT DETAILS -
TYPE
Supply Chain Attack, Data Breach
IMPACT
Data Compromised: AWS keys, over 300 private GitHub repositories (unreleased product source code, AI Assistants, AI Defense technologies, corporate client data)Systems Affected: Dozens of devices (lab workstations, developer systems, build environments)Operational Impact: Isolation of affected systems, mass credential reset, ongoing complications
DATA BREACH
Source codeCorporate dataAWS keysAI technologiesClient dataNumber Of Records Exposed: Over 300 private GitHub repositoriesSensitivity Of Data: High (unreleased product source code, AI Assistants, AI Defense technologies, corporate client data)
MARCH 2026
653Before Incident
Breach
11 Mar 2026 • Vendrive
Aura: Aura Data Breach Exposes Over 2 Million Records

Aura Data Breach Exposes Over 2 Million Records in Dark Web Leak

545After Incident
CRITICAL-108
USE1773865944
Aura Data Breach Exposes Over 2 Million Records in Dark Web Leak On March 11, 2026, digital security firm Aura confirmed a data breach after threat actor ShinyHunters posted claims on a dark web forum, alleging the theft of over two million records. The compromised data reportedly includes personally identifiable information (PII), such as names, email addresses, home addresses, and phone numbers. Aura stated that Social Security numbers, passwords, and financial details were not exposed, though the exact scope and timeline of the breach remain unconfirmed. ShinyHunters, a group linked to multiple high-profile breaches, claimed responsibility for the attack, though Aura has not disclosed how the intrusion occurred or when it was detected. The company is investigating the incident, and affected individuals are advised to monitor for potential fraud, though no direct notification process has been outlined. The breach highlights ongoing risks to corporate and consumer data, with exposed PII potentially enabling phishing campaigns or identity theft. Further details on the attack vector and mitigation efforts are pending.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Over 2 million recordsIdentity Theft Risk: Potential identity theft
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: Over 2 millionSensitivity Of Data: High (PII)Data Exfiltration: YesNamesEmail addressesHome addressesPhone numbers
MARCH 2026
750Before Incident
Breach
01 Mar 2026 • Vendrive
Aura: Aura confirms data breach exposing 900,000 marketing contacts

Aura Data Breach Affecting Nearly 900,000 Customers Following Vishing Attack

653After Incident
CRITICAL-97
USE1773879944
Aura Confirms Data Breach Affecting Nearly 900,000 Customers Following Vishing Attack Identity protection firm Aura has disclosed a data breach exposing nearly 900,000 customer records, including names, email addresses, home addresses, and phone numbers. The incident stemmed from a voice phishing (vishing) attack targeting an employee, which compromised data from 20,000 current and 15,000 former customers. The breach originated from a marketing tool used by a company acquired by Aura in 2021, which contained limited customer information. While Aura confirmed that Social Security Numbers (SSNs), passwords, and financial data were not accessed, the Have I Been Pwned (HIBP) service found that 90% of the exposed email addresses had already been compromised in prior breaches. The ShinyHunters threat group claimed responsibility for the attack, alleging they stole 12GB of files containing personally identifiable information (PII) and corporate data. The group leaked the data after claiming Aura failed to negotiate with them. Aura has not commented on ShinyHunters’ assertions or reports of an Okta SSO compromise. Aura is conducting an internal investigation with external cybersecurity experts and has notified law enforcement. Affected individuals will receive personalized notifications in the coming days. The company clarified that while 901,000 accounts were exposed, only 35,000 belonged to Aura customers, with the rest tied to the acquired firm’s legacy database.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion/Negotiation Failure
IMPACT
Data Compromised: Names, email addresses, home addresses, phone numbersSystems Affected: Marketing tool (legacy system from acquired company)Identity Theft Risk: HighPayment Information Risk: None
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: 901,000Sensitivity Of Data: Moderate (No SSNs, passwords, or financial data)Data Exfiltration: 12GB of files (alleged by ShinyHunters)Personally Identifiable Information: Names, email addresses, home addresses, phone numbers
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Vendrive ?
?
What was Vendrive's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Vendrive's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Vendrive's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Vendrive ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Vendrive's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?