MedusaLocker3/FarAttack Ransomware (.farattack, .itlock*, .busavelock*) Support – Ransomware Help & Tech Support

MedusaLocker3, also known as FarAttack, is an updated Rust-based ransomware variant that is being deployed alongside GlobeImposter 2.0, with both strains using the same file extensions in some attacks. The group leaves multiple ransom note formats and a long PERSONAL ID in the notes, while victims report signs of RDP compromise, Mimikatz use, and antivirus removal before encryption. #MedusaLocker3 #FarAttack #GlobeImposter20 #Mimikatz #RDP

Read More
Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale

The Municipality of Serpa was targeted by an external attack against its IT infrastructure, and the incident was promptly reported to the competent authorities, including the National Cybersecurity Center. While the system is considered secure, municipal services are still operating under constraints, including the loss of fixed and mobile communications. #MunicipalityofSerpa #NationalCybersecurityCenter #Serpa

Read More
Out of the Crypt: The Evolving Cyber Extortion Economy

Extortion campaigns are increasingly relying on data theft instead of encryption, with threat actors like ShinyHunters, CLOP, and TeamPCP using faster exfiltration, supply chain compromise, and vishing to pressure victims into paying. Regulators, class-action risk, and frontier AI models such as Mythos are reshaping the threat landscape by compressing attack timelines and making pure data extortion more effective. #ShinyHunters #CLOP #TeamPCP #BlingLibra #HazyScorpius #LAPSUS #Vect #BlackFile #Mythos

Read More
Rheinland-Pfalz: Kinderbilder von Plattform gestohlen – Das ist bekannt | tagesschau.de

Hackers breached Portraitbox, a photo service used by photographers in Rhineland-Palatinate, and stole children’s photos, email addresses, delivery addresses, and passwords. Authorities say the attackers are trying to extort the company, while affected families should change passwords and avoid clicking suspicious links. #Portraitbox #RheinlandPfalz #BSI

Read More
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs

This write-up reconstructs an Akira-attributed intrusion by joining SSLVPN syslog with Windows EVTX to show how the attackers gained access, escalated privileges, and prepared for ransomware deployment. It highlights that the most useful defensive evidence appears before encryption, including brute-force login attempts, Kerberoasting, RDP movement, log clearing, and shadow copy deletion. #Akira #Kerberoasting #nltest #vssadmin

Read More
Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories

TeamPCP claims to be directly selling stolen GitHub source code and internal data, while GitHub has confirmed that about 3,800 internal repositories were exfiltrated. The breach is linked to a compromised Visual Studio Code extension used in a supply-chain worm campaign that harvested credentials and exposed code for GitHub Copilot, GitHub…

Read More