Medusa ransomware has gone from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice. Plus how to validate your controls against each technique instead of assuming they catch it.

Read the full blog here: https://www.safebreach.com/blog/safebreach-coverage-us-cert-aa25-071a-medusa-ransomware/

#cybersecurity #infosec #CISO #MedusaRansomware #ransomware #CISAadvisory #BAS #cyberresilience

Podden och tillhörande omslagsbild på den här sidan tillhör SafeBreach. Innehållet i podden är skapat av SafeBreach och inte av, eller tillsammans med, Poddtoppen.