Gruppi Legati all'Iran Intensificano Attacchi Distruttivi e Supply‑Chain
Gruppi legati all'Iran hanno intensificato intrusioni distruttive, campagne ransomware e compromissioni della supply chain. Segnalazioni includono Pay2Key che ha cifrato un ambiente sanitario USA senza evidenza di esfiltrazione, Handala che ha presumibilmente abusato di Microsoft Intune per cancellazioni nei sistemi di Stryker, e TeamPCP che ha compromesso Trivy e avvelenato pacchetti npm con un worm e un wiper.
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.