The bug is in the SPNEGO Extended Negotiation Security Mechanism – which essentially allows a client and server to negotiate the choice of security mechanism that they use.
In earlier SafePay attacks the group has actively gone after backups and deleted Volume Shadow Copies (VSC) in an effort to inhibit recovery activities.
RDMS with separate Full-Text engine: Not a fast combination! It was time for a rethink -- and some help from Elastic
|
ransomware
|
Jul 01, 2025
Full-scale encryption, local exfiltration and self-cleanup into a single Rust binary.