logo

Microsoft links Medusa ransomware affiliate to zero-day attacks

ID: 8639be7a-c27a-5f8e-8b04-3d737da0c2ed

STIX ID: report--8639be7a-c27a-5f8e-8b04-3d737da0c2ed

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft reports that Storm-1175, a financially motivated cybercrime group deploying Medusa ransomware, has been rapidly weaponizing n-day and zero-day vulnerabilities—sometimes exploiting flaws days before patches—to gain access, chain exploits for persistence, steal credentials, disable defenses, and deploy ransomware. Recent campaigns have exploited more than 16 vulnerabilities across multiple products, impacted healthcare, education, professional services, and finance in AU/UK/US, and prompted a CISA/FBI/MS-ISAC advisory noting impacts to over 300 critical infrastructure organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.