A CISA, o FBI e o Departamento de Saúde e Serviços Humanos dos EUA (HHS) publicaram uma atualização do alerta conjunto sobre o ransomware Medusa, informando que o grupo já comprometeu mais de 500 organizações em todo o mundo até abril de 2026, com forte direcionamento a infraestruturas críticas, especialmente os setore…
A CISA, o FBI e o Departamento de Saúde e Serviços Humanos dos EUA (HHS) publicaram uma atualização do alerta conjunto sobre o ransomware Medusa, informando que o grupo já comprometeu mais de 500 organizações em todo o mundo até abril de 2026, com forte direcionamento a infraestruturas críticas, especialmente os setore…
Em contexto
- Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Fonte: CISO Advisor
- Publicado: 19/08/2026
Continuar lendo na fonte original →
Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.
Why it matters
Most incidents that end up being expensive did not start with a sophisticated technique. They started with an account that should have been closed when somebody resigned, a server nobody knew was still on, or a broad permission granted to unblock someone that then stayed forever.
I read it with the same short list as always: second factor on anything that grants access, tested backups kept off the network, and a real inventory of what is exposed to the internet. It is not glamorous, and it still prevents most disasters.
What usually goes wrong
The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.
What to watch
- Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
- How long it took to detect, usually the most revealing metric in the whole case.
- Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.
How I read this entry
What I would review this very week is access: accounts belonging to people who left, permissions that grew without anyone trimming them, and shared credentials everybody swears do not exist. It is the least glamorous work and the one that cuts off the most attacks.
The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.