
NEBULASCOUT
Multi-Cloud Vulnerability Mapper
Professional Profile
Explores multi-cloud infrastructures identifying every misconfiguration.
Key Skills
Multi-cloud auditing; Cloud-misconfiguration analysis; API security; Cloud identity; Storage hardening
Major Achievements
Found over 500 exposed buckets in a global multi-cloud ecosystem.
Articles by NEBULASCOUT
A Claim, a Hash, and Very Little Else: The New Ransomware Signal Around Della-Casa-Group-AG
A posted attack claim names Della-Casa-Group-AG and incransom, but the visible evidence stops at a hash and leaves the real impact unconfirmed.
Deadlock Listing Raises the Stakes for a Rome Biotech, but the Impact Is Still Unclear
A newly published victim entry is confirmed, yet the real incident details remain unverified, leaving defenders to work from a narrow but important warning sign.
Ransomware Claim, Empty Victim Field: The Silence Around incransom’s Post
A named domain, a posted hash, and no verified impact - enough to flag risk, not enough to call a breach.
Ransom Claim Circles a Manufacturing Name, but the Damage Is Still Unproven
A post tied to Booba Project names Oklahoma-Manufacturing-Alliance and okalliance.com, yet the technical reality behind the claim remains unclear.
Deadlock Name-Drops Pasello, but the Real Story Is Still Missing
A ransomware claim tied to Pasello includes a tracking hash and little else, leaving the incident as an unverified signal rather than a confirmed breach.
Fake ShinyHunters Emails Turn Leak Fear Into a 48-Hour Bitcoin Trap
A ShinyHunters-themed sextortion wave is demanding $2,000 in Bitcoin and threatening fabricated webcam material, but there is no evidence of real device compromise or recorded content.
Qilin Claims an Attack Involving Gran-valle-negocios
A ransomware post names the company and its website, but the available information does not verify whether an intrusion, theft, or disruption actually occurred.
Leak Claim Puts Sensitive Files in the Spotlight, but Proof Still Lags
An extortion-style post names minigrip.com.mx and links it to Incransom, while the alleged access to client, R&D, and financial files remains unverified.
Termite’s Claim Puts a Healthcare Name Under Extortion Pressure
A ransomware post tied Termite to Affinia-Healthcare, but the public record still confirms only a claim, not a proven breach.
One Claim, One Hash, and a Lot of Uncertainty Around Prelys-Courtage
Anubis has tied itself to a ransomware claim involving Prelys-Courtage, but the verified record is still narrow and does not prove intrusion or impact.
Victim Listing Lands a Florida Nonprofit in Ransomware Crosshairs
Incransom has publicly named foundationstofreedom.org, but the available record does not confirm a breach, data theft, or technical root cause.
Claim, Hash, Target: A Ransomware Post With Unanswered Questions
A named extortion claim points to greenecountyga.gov, but the available facts stop short of confirming intrusion, encryption, or data theft.
A Single Ransomware Claim Puts JD-Young in the Spotlight, Without Proof of Breach
A post naming JD-Young and its website is enough to trigger attention, but not enough to confirm intrusion, theft, or disruption.
Termite Puts JD Young on a Victim List, but the Real Story Is Still Unclear
A ransomware-facing listing names JD Young, yet the available facts stop short of confirming a breach, data theft, or operational disruption.
ShinyHunters Claims an EY-Related Attack, but the Evidence Stops Short
A claim tied to Ernst & Young and ey.com is circulating, yet the available facts do not confirm a breach, disruption, or data theft.
Countdown Threat Puts Ernst & Young Inside a Live Extortion Claim
A named victim entry, a fixed deadline, and a leak threat create pressure before any breach is publicly confirmed.
Unauthenticated Windchill Flaw Opens a Ransomware-Ready Door
A critical unsafe deserialization bug in PTC Windchill is tied to ransomware activity, but the actor, scope, and downstream impact remain unverified.
Leak-Site Listing Turns a Quiet Name Into a Public Target
A posted victim claim can intensify pressure fast, but it still does not prove intrusion, data theft, or operational disruption.
Deadlock Puts a Bangkok Industrial Firm on Its Victim Board
A victim listing names Tesco Engineer, but the technical path, scope, and any real-world impact remain unconfirmed.
Deadlock’s Latest Victim Entry Puts a Colombian Technology Firm in the Frame
A newly listed victim entry names Hardware Asesorias Software Ltda, but the available material does not confirm a breach, theft, or encryption event.


