Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.

Ep. 75 - The Franchise Model: How Medusa Turned Ransomware Into a Business

Medusa ransomware has went from 300 victims to more than 500, and CISA, FBI, and MS-ISAC just refreshed advisory AA25-071A with new IOCs and TTPs. Tova Dvorin and Adrian Culley unpack the ransomware-as-a-service franchise behind it: the ScreenConnect and Fortinet EMS CVEs still opening doors, three tiers of PowerShell obfuscation, gaze.exe killing shadow copies before AES-256 encryption, and the triple-extortion case where one victim was made to pay twice.

The Gap Between Security Dashboards and Decisions

Security teams often invest in more dashboards, more alerts, and more visibility. But when does visibility become noise? In this clip, David Clapp explains why security improvements come from actionability, not just awareness, and how organizations can close the gap between findings and decisions.

AWS Security Live from Black Hat 2026 with Johnny Wong from Veracode

In this episode, hosts Ryan and Brian are joined by Johnny Wong, VP of Solutions Architecture at Veracode, to explore how AI-assisted “vibe coding” is changing the way software gets built—and the new security risks that come with it. While large language models are making developers faster and more productive, studies shared in the discussion show that a significant portion of AI-generated code still contains security vulnerabilities, raising concerns about scale and speed in modern development pipelines.

Ship a Working Detection Pipeline in One Workshop: Headless SOC with Grid by LimaCharlie

By the end of this hands-on workshop, you will have deployed a working detection pipeline, ingested a cloud log source, and shipped a bespoke dashboard app, all using Claude Code integrated with Grid by LimaCharlie. Along the way, you will see how Grid compresses the traditional SIEM/EDR/SOAR stack into a single automated workspace. We go well beyond standard EDR and SIEM use cases. What to expect.

Run continuous compliance with Vanta

Plenty of tools can check a box at audit time. Vanta runs continuous compliance, so you're secure every day, not just the week before your audit. It runs on the Trust Graph, Vanta's data and intelligence layer that connects 400+ tools across your stack (cloud platforms, identity providers, task trackers, and more) and gives specialized agents the context to automate accurately. The difference isn't how many tools you connect. It's what happens after. In this video, you'll see Vanta in action.

How CrowdStrike Delivers Falcon Privileged Access

Breaches don’t always start with malware. Increasingly, adversaries simply log in with valid credentials and when those credentials come with standing privileges, attackers inherit that access instantly. In this Lightboard Lab, learn how CrowdStrike is rethinking traditional privileged access with Modern Privileged Access. See how continuous evaluation of identity, device trust, security risk and business context can eliminate standing privileges and help ensure the right person gets the right access, in the right context, right when they need it.