Uncle Sam urges action after Black Basta ransomware infects Ascension
ID: 9a6be5a7-d364-579f-8b38-d1579f9b3bfc
STIX ID: report--9a6be5a7-d364-579f-8b38-d1579f9b3bfc
Feed Name: The Register (Security)
CISA and Health-ISAC advisories describe Black Basta ransomware's widespread campaign (more than 500 targeted organizations since April 2022) and attribute a major disruption at healthcare provider Ascension to the group; the bulletin outlines common TTPs—spearphishing, use of loaders like Qakbot, post-compromise tooling (SystemBC, Mimikatz, CobaltStrike, Rclone), and exploitation of known CVEs—and recommends patching, phish-resistant MFA, securing remote access, reliable backups, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
