AUTO-UPDATED

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Recent cybersecurity reports highlight a surge in sophisticated threats, including Medusa ransomware attacks on 500 organizations and widespread data breaches affecting major corporate Azure tenants and French tax authorities.

Key Points

  • The Medusa ransomware gang has compromised over 500 organizations since June 2021, according to a joint advisory from the FBI, CISA, and HHS.
  • A threat actor known as "TheHatman" allegedly stole millions of employee records from Azure environments belonging to Fortune 500 companies like McDonald’s and Vodafone.
  • France’s tax authority confirmed a breach of the General Directorate of Public Finances (DGFiP), exposing the personal data of 678,000 individuals.
  • Researchers discovered a critical vulnerability in Windows 11 that allows attackers to bypass security protections without physical access to the machine.
  • Rapid7 reported 8,539 high- or critical-severity vulnerability disclosures in Q2 2026, doubling the volume of security flaws recorded during the same period last year.

Why it Matters

The rapid increase in both the volume of vulnerabilities and the sophistication of AI-driven attacks is forcing organizations to reevaluate their defensive strategies and incident response timelines. As threat actors leverage automation to exploit systems at machine speed, the widening gap in security visibility and credential management poses a significant risk to global enterprise infrastructure.
Help Net Security Published by Help Net Security
Read original