Security

CISA Warns Medusa Ransomware Has Hit 500 Critical-Infrastructure Orgs, Tags Two TrueConf Server Flaws as Actively Exploited

CISA, the FBI and HHS said on August 18 that the Medusa ransomware-as-a-service operation has breached more than 500 critical-infrastructure organizations since June 2021. A day later, the agency ordered federal agencies to patch two actively exploited flaws in TrueConf Server within two weeks.

M
By Marcus Reed Security Reporter
August 22, 2026 / Updated August 25, 2026 / 6 min read

The Cybersecurity and Infrastructure Security Agency, the FBI and the Department of Health and Human Services said on August 18, 2026 that the Medusa ransomware-as-a-service operation has breached more than 500 critical-infrastructure organizations since it first appeared in June 2021. The figure, drawn from FBI investigations through April 2026 and disclosed in an updated joint advisory, more than doubles the count cited in the previous March 2025 advisory, which had put the impact at over 300 organizations.

Who Medusa Has Hit

The agencies identified affected sectors as Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology and Financial Services. Outside critical infrastructure, victims include medical, education, legal, insurance, technology and manufacturing firms. Medusa actors operate opportunistically, targeting victims with unpatched software rather than focusing on specific organizations or sectors; however, the Healthcare and Public Health Sector has been a frequent victim because of its reliance on legacy systems and high-pressure operating environments that make downtime untenable. The advisory notes that Medusa leverages newly announced exploits within 24 hours of public disclosure and has been observed using exploits up to a week before public vulnerability disclosure.

How the Operation Works

Medusa uses a double-extortion model in which victim data is both encrypted and threatened with public release. Initial access brokers — middlemen who specialize in compromising corporate networks — are recruited via cybercriminal forums at rates reported to be as high as $100,000 per access. Affiliates are granted varying levels of trust based on experience and profitability; for newer or less-experienced affiliates, ransom negotiation is centrally controlled by the developers. Victims have 48 hours to respond to a ransom note via a Tor browser live chat or the Tox encrypted-messaging platform. The Medusa data-leak site publishes a countdown timer to release, and an additional $10,000 in cryptocurrency buys another day.

TrueConf Server Vulnerabilities Added to KEV

On August 20, CISA added two critical vulnerabilities in TrueConf Server — a self-hosted communications platform — to its Known Exploited Vulnerabilities Catalog. CVE-2026-72529 is a missing-authentication flaw that allows unauthenticated attackers to remotely execute arbitrary scripts; CVE-2026-72530 is a high-complexity code-injection vulnerability that can also lead to remote code execution. Kaspersky reported that the Head Mare hacktivist group has been exploiting both flaws since at least July 2026 to replace legitimate client installers with malicious versions designed to deploy backdoor malware. CISA ordered U.S. Federal Civilian Executive Branch agencies to secure their servers by September 3.

What It Means for Defenders

The combined signal from the two advisories is that the speed of exploitation is now outpacing the speed of patching for organizations that rely on legacy on-premises communications and file-sharing systems. Medusa's 24-hour exploit-to-deployment cycle, combined with the pre-disclosure exploitation observed in some campaigns, means defenders cannot rely on patch-Tuesday cadences. The agencies recommended network segmentation to block lateral movement, blocking access from untrusted origins to remote services, and immediate patching of internet-facing systems — and continued to discourage paying ransoms because payment does not guarantee file recovery and emboldens further attacks.

What to Watch Through Year-End

Three checkpoints follow. CISA's next quarterly KEV catalog update, expected in October, will show whether the pace of actively exploited vulnerabilities disclosed by independent vendors has continued to accelerate after a record-setting 2025. The Department of Health and Human Services, newly added as a co-sealer of the Medusa advisory, is expected to publish its first sector-specific ransomware-impact report in November. And the next round of indictments, if any, in the long-running Medusa investigation will likely name additional Russian-speaking affiliates operating in jurisdictions without extradition treaties with the United States.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.