Medusa ransomware group using zero-days to launch attacks within 24 hours of breach, Microsoft says
ID: 4f60d7d5-53c6-5063-b674-400789366c43
STIX ID: report--4f60d7d5-53c6-5063-b674-400789366c43
Feed Name: The Record from Recorded Future News
Medusa ransomware operators are actively exploiting newly disclosed vulnerabilities—sometimes days before public disclosure—to quickly compromise organizations (notably a major US hospital and a New Jersey county). Microsoft reports the group moves from access to exfiltration and encryption within 24 hours in many cases, leverages legitimate remote-management tools for lateral movement and persistence, and targets web-facing systems during the disclosure-to-patch window, impacting healthcare, education, professional services, and finance across multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
