Vendrive A.I CyberSecurity Scoring
Vendrive
Company Information
Website:https://goaura.com/
Employees number:7
Number of followers:663
NAICS:5112
Industry Type:Software Development
Homepage:goaura.com
Vendrive Risk Score (AI oriented)
Between 0 and 549
VendriveSoftware Development
Updated:
01/04/2026
01/04/2026
541/1000
Critical
C
Vendrive Global Score (TPRM)
xxxx
VendriveSoftware Development
Score locked

VendriveCritical
Current Score
541C (CRITICAL)
01000
3 incidents
-70.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
562
AUGUST 2026
558
JULY 2026
555
JUNE 2026
552
MAY 2026
549
APRIL 2026
547
Vulnerability
01 Apr 2026 • Vendrive
Trivy, Cisco, Salesforce, AWS and Aura: Cisco Faces Alleged Data Leak as ShinyHunters Claims Responsibility
Cisco Hit by Major Cyberattack Linked to Supply Chain Breach
541
CRITICAL-6
AQUUSEAMASALCIS1775046662
Cisco Hit by Major Cyberattack Linked to Supply Chain Breach
Cisco is responding to a significant cybersecurity incident after threat actors breached its internal development networks, stealing sensitive source code and corporate data. The attack, claimed by the hacking group ShinyHunters, also allegedly impacted Salesforce, Aura, and AWS storage buckets.
The breach originated from a supply chain attack involving Trivy, a widely used vulnerability scanner. Attackers exploited a malicious GitHub Action plugin tied to the Trivy compromise, allowing them to steal credentials and infiltrate Cisco’s build environments. Once inside, they compromised dozens of devices, including lab workstations and developer systems, gaining access to highly sensitive data.
The stolen material includes AWS keys, which were used to perform unauthorized actions in Cisco’s cloud accounts, and over 300 private GitHub repositories. These repositories contain unreleased product source code, including AI Assistants and AI Defense technologies, as well as data belonging to corporate clients, such as major banks, BPO firms, and U.S. government agencies.
Cisco’s security teams including the Unified Intelligence Center, CSIRT, and EOC moved quickly to contain the breach by isolating affected systems, wiping compromised machines, and enforcing a mass credential reset. However, the company has not yet issued a public statement, and internal sources suggest ongoing complications from the incident.
While ShinyHunters has taken credit for the data theft, security researchers link the underlying Trivy supply chain attack to TeamPCP, a separate group known for deploying custom malware ("TeamPCP Cloud Stealer") to hijack developer platforms like Docker, NPM, and PyPi. TeamPCP has also been tied to recent breaches of LiteLLM and Checkmarx, raising concerns about secondary attacks stemming from related vulnerabilities.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
653
Breach
11 Mar 2026 • Vendrive
Aura: Aura Data Breach Exposes Over 2 Million Records
Aura Data Breach Exposes Over 2 Million Records in Dark Web Leak
545
CRITICAL-108
USE1773865944
Aura Data Breach Exposes Over 2 Million Records in Dark Web Leak
On March 11, 2026, digital security firm Aura confirmed a data breach after threat actor ShinyHunters posted claims on a dark web forum, alleging the theft of over two million records. The compromised data reportedly includes personally identifiable information (PII), such as names, email addresses, home addresses, and phone numbers. Aura stated that Social Security numbers, passwords, and financial details were not exposed, though the exact scope and timeline of the breach remain unconfirmed.
ShinyHunters, a group linked to multiple high-profile breaches, claimed responsibility for the attack, though Aura has not disclosed how the intrusion occurred or when it was detected. The company is investigating the incident, and affected individuals are advised to monitor for potential fraud, though no direct notification process has been outlined.
The breach highlights ongoing risks to corporate and consumer data, with exposed PII potentially enabling phishing campaigns or identity theft. Further details on the attack vector and mitigation efforts are pending.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
750
Breach
01 Mar 2026 • Vendrive
Aura: Aura confirms data breach exposing 900,000 marketing contacts
Aura Data Breach Affecting Nearly 900,000 Customers Following Vishing Attack
653
CRITICAL-97
USE1773879944
Aura Confirms Data Breach Affecting Nearly 900,000 Customers Following Vishing Attack
Identity protection firm Aura has disclosed a data breach exposing nearly 900,000 customer records, including names, email addresses, home addresses, and phone numbers. The incident stemmed from a voice phishing (vishing) attack targeting an employee, which compromised data from 20,000 current and 15,000 former customers.
The breach originated from a marketing tool used by a company acquired by Aura in 2021, which contained limited customer information. While Aura confirmed that Social Security Numbers (SSNs), passwords, and financial data were not accessed, the Have I Been Pwned (HIBP) service found that 90% of the exposed email addresses had already been compromised in prior breaches.
The ShinyHunters threat group claimed responsibility for the attack, alleging they stole 12GB of files containing personally identifiable information (PII) and corporate data. The group leaked the data after claiming Aura failed to negotiate with them. Aura has not commented on ShinyHunters’ assertions or reports of an Okta SSO compromise.
Aura is conducting an internal investigation with external cybersecurity experts and has notified law enforcement. Affected individuals will receive personalized notifications in the coming days. The company clarified that while 901,000 accounts were exposed, only 35,000 belonged to Aura customers, with the rest tied to the acquired firm’s legacy database.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Vendrive ??
What was Vendrive's A.I Rankiteo Cyber Score in August 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in July 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in June 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in May 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in April 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in March 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in February 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in January 2026 ??
What was Vendrive's A.I Rankiteo Cyber Score in December 2025 ??
What was Vendrive's A.I Rankiteo Cyber Score in November 2025 ??
What was Vendrive's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Vendrive's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Vendrive ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Vendrive's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?