Medusa ransomware has gone from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice. Plus how to validate your controls against each technique instead of assuming they catch it.
Podden och tillhörande omslagsbild på den här sidan tillhör
SafeBreach. Innehållet i podden är skapat av SafeBreach och inte av,
eller tillsammans med, Poddtoppen.