Back to the radar Cybersecurity

Ransomware Medusa já fez mais de 500 vítimas

Cybersecurity

A CISA, o FBI e o Departamento de Saúde e Serviços Humanos dos EUA (HHS) publicaram uma atualização do alerta conjunto sobre o ransomware Medusa, informando que o grupo já comprometeu mais de 500 organizações em todo o mundo até abril de 2026, com forte direcionamento a infraestruturas críticas, especialmente os setore…

A CISA, o FBI e o Departamento de Saúde e Serviços Humanos dos EUA (HHS) publicaram uma atualização do alerta conjunto sobre o ransomware Medusa, informando que o grupo já comprometeu mais de 500 organizações em todo o mundo até abril de 2026, com forte direcionamento a infraestruturas críticas, especialmente os setore…

Em contexto

  • Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
  • Fonte: CISO Advisor
  • Publicado: 19/08/2026

Continuar lendo na fonte original →

Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.

Why it matters

Most incidents that end up being expensive did not start with a sophisticated technique. They started with an account that should have been closed when somebody resigned, a server nobody knew was still on, or a broad permission granted to unblock someone that then stayed forever.

I read it with the same short list as always: second factor on anything that grants access, tested backups kept off the network, and a real inventory of what is exposed to the internet. It is not glamorous, and it still prevents most disasters.

What usually goes wrong

The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.

What to watch

  • Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
  • How long it took to detect, usually the most revealing metric in the whole case.
  • Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.

How I read this entry

What I would review this very week is access: accounts belonging to people who left, permissions that grew without anyone trimming them, and shared credentials everybody swears do not exist. It is the least glamorous work and the one that cuts off the most attacks.

The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Share

Living through this in your own team?

Open the chat and tell me how you're handling it. I'm interested in comparing notes.

Keep reading

More entries from the radar

See all
Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.