First 30 minutes: Open six separate incident threads—TeamCity, Oracle, Zimbra, Metabase, Gitea, and Medusa—with separate owners, timelines, and evidence stores. TeamCity leads only when it is exposed or controls production builds, signing, or deployment; otherwise an internet-facing Zimbra, Gitea, Metabase, or critical Oracle service can legitimately jump the queue. Remove vulnerable services from untrusted ingress before patching, while preserving: TeamCity build/agent/artifact/VCS logs; Oracle listener/audit/session/job and privilege records; Zimbra proxy/mail/admin logs, forwarding rules and webroot; Metabase application/query/audit records and database connections; and Gitea HTTP/auth logs, repository refs, hooks, runners, releases, and token activity.
Tonight: Snapshot or clone isolated hosts, capture running processes and connections, then patch only after evidence collection. Rebuild from trusted media rather than patch in place if there is web-shell or command-execution evidence, persistence, unauthorized administrators/hooks/jobs, altered builds or repositories, erased logs, or uncertain host integrity. From clean administration systems, terminate application sessions, revoke OAuth grants and service/deployment tokens, then rotate credentials and potentially signing trust; passwords alone do not close this incident. Run Medusa separately using CISA’s current IOCs and TTPs to hunt for remote-access abuse, credential theft, lateral movement, backup interference, and encryption staging—the advisory reports more than 500 victims, but Lena found no basis to attribute these five exploitation threads to Medusa or Laundry Bear.
Tomorrow: Reopen each service independently only when the fixed or mitigated state is verified, integrity is restored or rebuilt, unauthorized accounts/configuration changes are removed, old sessions and tokens demonstrably fail, replacement secrets originate from clean systems, and EDR/log forwarding plus restricted ingress are operating. Keep a decision and evidence log; Sofia’s notification assessment starts when investigation shows organization-specific access, exfiltration, disruption, or materiality—not exposure by itself.