Medusa does not write zero-days. It just weaponizes yours within 24 hours of disclosure.

On August 18, the FBI, CISA and HHS published an updated #StopRansomware advisory: Medusa has now impacted more than 500 victims across critical infrastructure — up from 300 in the February 2025 count. Medical, education, legal, insurance, technology and manufacturing, with healthcare hit hardest.

WHAT ACTUALLY HAPPENED

The advisory documents a ransomware-as-a-service operation that has significantly expanded its initial access and post-exploitation tooling since February 2025.

The defining behavior: Medusa affiliates leverage newly announced exploits within 24 hours of publication, with no evidence the group develops its own zero-days. Extortion follows a double-extortion model — victims get 48 hours to respond to the ransom note before affiliates begin contacting them directly, and stolen data goes onto a leak site with a countdown timer.

WHY THE 24-HOUR NUMBER IS THE WHOLE ADVISORY

Most enterprise patch cycles are measured in weeks. Change advisory boards meet weekly. Maintenance windows land monthly. Medusa's exploitation window is measured in hours.

That gap is not a resourcing problem you can hire your way out of — it is a process mismatch. As long as "urgent" in your organization means "next maintenance window," a commodity RaaS crew with no original research capability will keep beating you on timing using nothing but public information.

WHAT TO DO NOW

BUILD A SAME-DAY LANE FOR KEV ADDITIONS — internet-facing systems on the CISA KEV list need an emergency path that bypasses the normal change queue, pre-approved before you need it.

  • ENFORCE PHISHING-RESISTANT MFA ON EVERY REMOTE ENTRY POINT VPN, RMM, webmail and remote desktop are the doors this crew keeps finding open.

TEST RESTORES, NOT BACKUPS — offline, immutable copies matter only if you have proven you can rebuild a domain controller from them under pressure.

REHEARSE THE 48-HOUR CLOCK — decide now, in writing, who talks to the attacker, who calls the regulator, and who calls the insurer, because the countdown is not the moment to draft that.

Your adversary reads the same advisories you do. They just act on them faster.

How many hours pass between a KEV addition and a patch on your internet edge?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.