CVE Tools

Medusa ransomware gang has hit over 500 organizations, CISA warns

Help Net SecurityBy Sinisa Markovic

Reported exploitedScreenConnectMedusa

Our summary

FBI, CISA, and HHS have issued an updated joint advisory revealing that the Medusa ransomware group has compromised more than 500 organizations since 2021. The agencies report that victims span critical sectors including healthcare, defense, manufacturing, and finance, with many organizations affected through unpatched vulnerabilities in products such as ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust.

Medusa operates via an affiliate model where operators deploy newly disclosed exploits within 24 hours of announcement rather than developing zero-days. To mitigate risk, defenders should immediately patch internet-facing systems, segment networks to restrict lateral movement, and block unauthorized remote access traffic.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store