North Korean Lazarus Group Now Working With Medusa Ransomware

North Korean attackers continuing to mount extortion attacks against the U.S. healthcare sector despite indictment.

One misstep exposed sensitive data of over 1.2 million patients—find out how the SimonMed breach by Medusa ransomware is shaking up healthcare security and what it means for all of us.

https://thedefendopsdiaries.com/the-simonmed-imaging-breach-lessons-in-healthcare-data-security/

#healthcarecybersecurity
#databreach
#ransomware
#patientprivacy
#infosec
#medusaransomware
#hipaacompliance
#cyberthreats
#datasecurity

🚨 Microsoft confirms Storm-1175 exploiting GoAnywhere MFT (CVE-2025-10035) in ongoing Medusa ransomware attacks.

The attacks:
- Remote deserialization vulnerability
- Lateral movement with RMM tools
- Exfiltration via Rclone
- Medusa ransomware payload deployment
💬 Security teams: Patch GoAnywhere instances immediately and monitor log files for SignedObject.get Object stack traces.

Follow @technadu for timely cybersecurity updates.

#CyberSecurity #GoAnywhereMFT #MedusaRansomware #RMMTools #ThreatIntel #DataProtection #IncidentResponse #InfoSec #TechNadu

One overlooked bug in GoAnywhere MFT sparked a wave of ransomware attacks on over 500 systems. How did cybercriminals hide in plain sight using legit IT tools? Find out the tactics behind the chaos.

https://thedefendopsdiaries.com/exploitation-of-goanywhere-mft-vulnerability-by-storm-1175-impact-tactics-and-lessons-learned/

#goanywhere
#ransomware
#storm1175
#cve202510035
#cyberattack
#medusaransomware
#remotemanagement
#databreach
#patchmanagement

Exploitation of GoAnywhere MFT Vulnerability by Storm-1175: Impact, Tactics, and Lessons Learned

Explore how Storm-1175 exploited the GoAnywhere MFT vulnerability, unleashing ransomware attacks and data breaches, plus key lessons for defense.

The DefendOps Diaries

Imagine a ransomware gang bold enough to try recruiting a BBC reporter—Medusa’s tactics are evolving fast and targeting insiders. How safe are our defenses?

https://thedefendopsdiaries.com/medusa-ransomware-evolving-tactics-and-the-growing-insider-threat/

#medusaransomware
#ransomware
#insiderthreat
#cybersecurity2025
#doubleextortion

Medusa Ransomware: Evolving Tactics and the Growing Insider Threat

Explore how Medusa ransomware's evolving tactics and insider recruitment are reshaping cyber threats and what organizations must do to defend.

The DefendOps Diaries

🚨 NASCAR has confirmed a data breach caused by a March 2025 cyberattack.

SSNs were exposed. Medusa ransomware group claimed responsibility. Victims were notified on July 24 and offered credit monitoring.

No confirmation yet on how much data was exfiltrated or if it was leaked.

#Cybersecurity #Ransomware #NASCAR #DataBreach #MedusaRansomware #ThreatIntel

Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play.

Shedding light on the ABYSSWORKER driver — Elastic Security Labs

Elastic Security Labs describes ABYSSWORKER, a malicious driver used with the MEDUSA ransomware attack-chain to disable anti-malware tools.

🖥️ CYBERSECURITY
🔴 FBI Warns of Medusa Ransomware Targeting Gmail & Outlook

🔸 Medusa ransomware has hit 300+ victims since 2021.
🔸 Uses phishing & unpatched software flaws to access data.
🔸 Victims face triple extortion; one case involved hackers claiming others stole the ransom.
🔸 FBI urges strong passwords, MFA, and frequent backups.

#CyberSecurity #MedusaRansomware #Gmail #Outlook #FBI