logo

FulcrumSec Playbook: Sådan opdager og stopper du gruppen bag Novo Nordisk-bruddet

ID: c373003e-ed45-5b56-a556-964aa137ff4d

STIX ID: report--c373003e-ed45-5b56-a556-964aa137ff4d

Feed Name: Sysdig Blog

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-27

...
...

This report profiles FulcrumSec, a financially motivated group that targets cloud-native organizations by exploiting exposed credentials, unpatched internet-facing apps (e.g., CVE-2025-55182), and misconfigured cloud storage to harvest secrets, quietly collect and exfiltrate large volumes of sensitive data (multiple terabytes), and then extort victims using a “steal and squeeze” model; it documents their multi-stage playbook and provides detection and mitigation recommendations focused on secret management, least-privilege for machine identities, accelerated patching, and behavioral detection across identity, cloud control plane, and runtime.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.