• CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware

    From CISA@cisa@messages.cisa.gov to cisa@toolazy.synchro.net on Tue Aug 18 15:15:57 2026
    --===============9078673484532779971==
    Content-Type: multipart/alternative; boundary="===============3327291452010063149=="
    MIME-Version: 1.0

    --===============3327291452010063149==
    Content-Type: text/plain; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    Cybersecurity and Infrastructure Security Agency (CISA)

    You are subscribed to Cybersecurity Advisories for Cybersecurity and Infras= tructure Security Agency. This information has recently been updated and is=
    now available.

    CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware =
    [ https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a?utm_s= ource=3DMedusaRansomware2026&utm_medium=3DGovDelivery ]
    08/18/2026 11:15 AM EST=20

    The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bu= reau of Investigation (FBI), and the U.S. Department of Health and Human Se= rvices (HHS) released an update to the joint Cybersecurity Advisory #StopRa= nsomware: Medusa Ransomware [ https://www.cisa.gov/news-events/cybersecurit= y-advisories/aa25-071a?utm_source=3DMedusaRansomware2026&utm_medium=3DGovDe= livery ]. The advisory is part of an ongoing series detailing ransomware va= riants and threat actors. It provides technical details on Medusa ransomwar=
    e activity, along with detection and mitigation guidance to help protect at= -risk government and critical infrastructure organizations.

    Medusa is a ransomware-as-a-service variant first identified in June 2021. =
    As of April 2026, Medusa actors have impacted more than 500 victims across = multiple critical infrastructure sectors, including Healthcare and Public H= ealth, Defense Industrial Base, Critical Manufacturing, Government Services=
    and Facilities, Information Technology, and Financial Services. Other vict= ims include organizations in the medical, education, legal, insurance, tech= nology, and manufacturing industries.

    The updated advisory details how Medusa actors gain initial access through = brokers, phishing, and exploitation of newly disclosed, unpatched internet-= facing vulnerabilities [ https://www.cve.org/About/Overview ]. Medusa actor=
    s often use legitimate tools and living off the land techniques [ https://w= ww.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-lan= d-techniques ] to evade detection. They may also leverage remote monitoring=
    and management software and remote access services, including Remote Deskt=
    op Protocol, for lateral movement. Once inside a network, they use common u= tilities and tools to support credential access, data exfiltration, and ran= somware deployment. Medusa uses a double-extortion model, encrypting system=
    s and threatening to publish exfiltrated data if victims do not pay.

    CISA, FBI, and HHS urge organizations to implement the advisory=E2=80=99s m= itigations, including these key actions:


    * Mitigate known vulnerabilities [ https://www.cisa.gov/known-exploited-v= ulnerabilities-catalog ] by ensuring operating systems, software, and firmw= are are patched and up to date within a risk-informed timeframe.=20
    * Segment networks to restrict lateral movement from initially infected d= evices to other devices in the organization.=20
    * Filter network traffic by preventing unknown or untrusted origins from = accessing remote services on internal systems.=20

    Read the joint advisory [ https://www.cisa.gov/news-events/cybersecurity-ad= visories/aa25-071a?utm_source=3DMedusaRansomware2026&utm_medium=3DGovDelive=
    ry ] for indicators of compromise, incident response actions, mitigations, = and other recommendations to protect your organization from Medusa. For mor=
    e information on the #StopRansomware series, visit CISA=E2=80=99s Stop Rans= omware webpage [ https://www.cisa.gov/stopransomware ].

    Please share your thoughts with us through this anonymous survey [ https://= cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliv= eryMedusaRansomware2026 ]. We appreciate your feedback.

    This product is provided subject to this Notification [ https://www.cisa.go= v/notification ] and this Privacy & Use [ https://www.cisa.gov/privacy-poli=
    cy ] policy.

    body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
    : normal; font-style: normal; color: #333333; }=20

    Having trouble viewing this message?=C2=A0View it as a webpage [ https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/4258863 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]

    You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [ https://www.cisa.gov ] (CISA)
    Manage Subscriptions [ https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [ https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]

    Connect with CISA:=20
    Facebook [ https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [ https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [ https://Instagram.com/cisag=
    ov ]=C2=A0 |=C2=A0 LinkedIn [ https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]

    ________________________________________________________________________


    This email was sent to cisa@toolazy.synchro.net using Granicus Communicatio=
    ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ h= ttps://granicus.com/solution/digital-communication-engagement/ ]=20
    body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
    y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}

    --===============3327291452010063149==
    Content-Type: text/html; charset="utf-8"
    MIME-Version: 1.0
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns=3D"http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
    <title> CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa = Ransomware
    </title>


    </head>
    <body style=3D"">

    <table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
    align=3D"center">
    <tr>
    <td>

    <!--[if (gte mso 9)|(IE)]>
    <table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
    <![endif]-->
    <a name=3D"gd_top" id=3D"gd_top"></a>

    =20



    <p><img src=3D"https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
    <p>You are subscribed to Cybersecurity Advisories for Cybersecurity and I= nfrastructure Security Agency. This information has recently been updated a=
    nd is now available.</p>
    <div class=3D"rss_item" style=3D"margin-bottom: 2em;">
    <h1 class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margin=
    : 0 0 0.3em; padding: 0;"><a href=3D"https://www.cisa.gov/news-events/cyber= security-advisories/aa25-071a?utm_source=3DMedusaRansomware2026&utm_medium= =3DGovDelivery" target=3D"_blank" title=3D"CISA, FBI and HHS Update Joint C= ybersecurity Advisory on Medusa Ransomware" rel=3D"noopener">CISA, FBI and = HHS Update Joint Cybersecurity Advisory on Medusa Ransomware</a></h1>
    <div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">08/18/2026 11:15 AM EST</div> <div class=3D"l-page-section l-page-section--rich-text csaf-imported">

    <div class=3D"l-constrain">
    <div class=3D"l-page-section__content">
    <p>The Cybersecurity and Infrastructure Security Agency (CISA), the Federal=
    Bureau of Investigation (FBI), and the U.S. Department of Health and Human=
    Services (HHS) released an update to the joint Cybersecurity Advisory <a h= ref=3D"https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a?= utm_source=3DMedusaRansomware2026&utm_medium=3DGovDelivery" target=3D"_blan=
    k" title=3D"#StopRansomware: Medusa Ransomware" rel=3D"noopener">#StopRanso= mware: Medusa Ransomware</a>. The advisory is part of an ongoing series det= ailing ransomware variants and threat actors. It provides technical details=
    on Medusa ransomware activity, along with detection and mitigation guidanc=
    e to help protect at-risk government and critical infrastructure organizati= ons.</p>
    <p>Medusa is a ransomware-as-a-service variant first identified in June 202=
    1. As of April 2026, Medusa actors have impacted more than 500 victims acro=
    ss multiple critical infrastructure sectors, including Healthcare and Publi=
    c Health, Defense Industrial Base, Critical Manufacturing, Government Servi= ces and Facilities, Information Technology, and Financial Services. Other v= ictims include organizations in the medical, education, legal, insurance, t= echnology, and manufacturing industries.</p>
    <p>The updated advisory details how Medusa actors gain initial access throu=
    gh brokers, phishing, and exploitation of newly disclosed, unpatched intern= et-facing <a href=3D"https://www.cve.org/About/Overview" target=3D"_blank" = title=3D"vulnerabilities" rel=3D"noopener">vulnerabilities</a>. Medusa acto=
    rs often use legitimate tools and <a href=3D"https://www.cisa.gov/resources= -tools/resources/identifying-and-mitigating-living-land-techniques" target= =3D"_blank" title=3D"living off the land techniques" rel=3D"noopener">livin=
    g off the land techniques</a> to evade detection. They may also leverage re= mote monitoring and management software and remote access services, includi=
    ng Remote Desktop Protocol, for lateral movement. Once inside a network, th=
    ey use common utilities and tools to support credential access, data exfilt= ration, and ransomware deployment. Medusa uses a double-extortion model, en= crypting systems and threatening to publish exfiltrated data if victims do = not pay.</p>
    <p>CISA, FBI, and HHS urge organizations to implement the advisory=E2=80=99=
    s mitigations, including these key actions:</p>

    <li>Mitigate <a href=3D"https://www.cisa.gov/known-exploited-vulnerabilitie= s-catalog" target=3D"_blank" title=3D"known vulnerabilities" rel=3D"noopene= r">known vulnerabilities</a> by ensuring operating systems, software, and f= irmware are patched and up to date within a risk-informed timeframe.</li> <li>Segment networks to restrict lateral movement from initially infected d= evices to other devices in the organization.</li>
    <li>Filter network traffic by preventing unknown or untrusted origins from = accessing remote services on internal systems.</li>
    </ul>
    <p>Read the <a href=3D"https://www.cisa.gov/news-events/cybersecurity-advis= ories/aa25-071a?utm_source=3DMedusaRansomware2026&utm_medium=3DGovDelivery"=
    target=3D"_blank" title=3D"joint advisory" rel=3D"noopener">joint advisory=
    </a> for indicators of compromise, incident response actions, mitigations, =
    and other recommendations to protect your organization from Medusa. For mor=
    e information on the #StopRansomware series, visit <a href=3D"https://www.c= isa.gov/stopransomware" target=3D"_blank" title=3D"CISA=E2=80=99s Stop Rans= omware webpage" rel=3D"noopener">CISA=E2=80=99s Stop Ransomware webpage</a>= .</p>
    <p><br>Please share your thoughts with us through this <a href=3D"https://c= isasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDelive= ryMedusaRansomware2026" target=3D"_blank" title=3D"anonymous survey" rel=3D= "noopener">anonymous survey</a>. We appreciate your feedback.</p>

    <p>This product is provided subject to this <a href=3D"https://www.cisa.gov= /notification" target=3D"_blank" rel=3D"noopener">Notification</a> and this=
    <a href=3D"https://www.cisa.gov/privacy-policy" target=3D"_blank" rel=3D"n= oopener">Privacy &amp; Use</a> policy.</p>
    </div>
    </div>
    </div>
    </div>
    <style>body {
    font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
    l; font-style: normal; color: #333333;
    }
    </style>
    =20


    <div id=3D"mail_footer">
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
    r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/4258863" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"https://www.cisa.gov/privacy-policy=
    " target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
    r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
    <p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
    : #757575;">=C2=A0 |=C2=A0 </span><a href=3D"https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
    an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>

    </div>
    <div id=3D"tagline">
    <hr>
    <table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=

    <tbody>

    <td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
    <td align=3D"right" width=3D"11%"><a href=3D"https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"GovDelivery logo" width=3D"115"></a></td>
    </tr>
    </tbody>
    </table>
    <style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
    img {margin-left:0px; margin-right:0px;}</style>

    </div>
    </td>
    </tr>
    </table>

    <img alt=3D"" src=3D"https://links-2.govdelivery.com/CI0/010101a01571884f-7= 82c4eaf-b4be-43f6-91a7-eb71338fd365-000000/xfaJvk2OAYvM7ERMsGdd_xBWdORMN7-f= -kD5xY3ErVU=3D452" style=3D"display: none; width: 1px; height: 1px;">
    </body>
    </html>

    --===============3327291452010063149==--

    --===============9078673484532779971==--