Skip to content

Threat Intelligence

Tyler McLellan

Principal Threat Analyst | Emerging Threats • Automation • AI-Driven Defense

Analyzing high-impact threats at scale. Expert in major incident response, software supply chain integrity, and the intersection of AI and Cyber Threat Intelligence (CTI).

Core Specialties

Operational depth across the modern threat landscape.

Research designed to move quickly from investigation into defender action, with emphasis on high-impact intrusions and scalable analysis systems.

01

Emerging Threats

Expertise in zero-day exploitation and edge device security, including high-profile campaigns targeting Ivanti and Citrix infrastructure.

02

Automation & AI

Building scalable systems to detect, analyze, and disrupt global threat actor infrastructure with faster and more consistent defensive workflows.

03

Supply Chain Security

Identifying malicious NPM and PyPI packages, tracing upstream compromise, and surfacing abuse before it cascades across the software ecosystem.

04

Major Incidents

Technical lead for globally significant intrusions involving APT44, Turla, and Sandworm, with emphasis on fast-moving operational response.

Research Archive

Selected reports, investigations, and whitepapers.

Showing 10 reports

Date
Title

North Korea-Nexus Threat Actor Compromises Axios NPM Package

Category

Supply Chain

Date
Title

Widespread Data Theft Targets Salesforce via Salesloft Drift

Category

Major Incident

Date
Title

APT44: Unearthing Sandworm

Category

APT / Infrastructure

Date
Title

Investigating Ivanti Connect Secure VPN Zero-Day

Category

Emerging Threats

Date
Title

Sandworm Disrupts Power in Ukraine

Category

Major Incident / OT

Date
Title

ALPHV Ransomware Affiliate UNC4466 Analysis

Category

Ransomware

Date
Title

Turla: A Galaxy of Opportunity

Category

Infrastructure

Date
Title

Cloud Metadata Abuse by UNC2903

Category

Cloud Security

Date
Title

UNC2596 and Cuba Ransomware

Category

Ransomware

Date
Title

DARKSIDE Affiliate Supply Chain Compromise

Category

Supply Chain

Connect

Follow ongoing research and threat intelligence work.

LinkedIn is the primary channel for professional conversation and current updates.

Visit LinkedIn