Lazarus Group Hits Healthcare and SolarWinds Fixes Root [Prime Cyber Insights]

The Lazarus Group has shifted tactics by deploying Medusa ransomware against healthcare entities in the U.S. and Middle East, moving toward off-the-shelf ransomware-as-a-service models. Meanwhile, SolarWinds issued emergency patches for four critical vulnerabilities in its Serv-U file transfer software, including CVE-2025-40538, which could grant attackers root or admin permissions. The episode also explores a newly disclosed 2021 Ivanti VPN backdoor that impacted over 100 organizations, highlighting the security risks associated with private equity-driven cost-cutting. Additionally, we cover the Qilin ransomware attack on New York's transit workers' union, the ShinyHunters extortion claim against Dutch telecom Odido, and research showing that nearly a third of Meta ads in Europe are malicious. Finally, we look at NASA's successful Artemis II fueling test which clears the path for a March lunar mission.

Today on Prime Cyber Insights, we examine a coordinated wave of cyber threats targeting healthcare, infrastructure, and enterprise software. We lead with the Lazarus Group’s pivot to Medusa ransomware, a move that demonstrates a tactical shift toward established cybercrime affiliate models. We also break down the critical patches from SolarWinds for Serv-U vulnerabilities that offer a direct path to root access. Our coverage extends to the breach of the NYC Transit workers' union by Qilin ransomware and the massive data extortion claims hitting Dutch telecom Odido. We are joined by guest Chad Thompson to provide a systems-level perspective on how automation and enterprise risk are evolving in the face of these persistent threats. We also look at the resilience of NASA's Artemis II mission following its successful fueling trials.

Topics Covered

  • 🚨 Lazarus Group’s adoption of Medusa ransomware for healthcare extortion.
  • 🔐 Critical root-access vulnerabilities patched in SolarWinds Serv-U software.
  • 🌐 The 2021 Ivanti VPN backdoor and the impact of corporate restructuring on security.
  • 🚆 Qilin ransomware hits the NYC Transit workers' union chapter.
  • 📱 ShinyHunters extortion gang claims a massive breach of telecom provider Odido.
  • 🚀 NASA’s successful Artemis II fueling test ahead of the March launch window.

Disclaimer: The information provided is based on reports current as of February 24, 2026.

Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com.

  • (00:06) - Introduction
  • (00:06) - SolarWinds and Lazarus Threats
  • (01:46) - Conclusion
  • (01:46) - VPN and Telecom Breaches
  • (01:46) - Infrastructure and Lunar Resilience
Lazarus Group Hits Healthcare and SolarWinds Fixes Root [Prime Cyber Insights]
Broadcast by