FBI, CISA and HHS updated advisory AA25-071A on August 18, and the Medusa ransomware count now stands above 500 victims across critical infrastructure sectors as of April 2026. Healthcare and public health remains on the short list of most-hit sectors, alongside manufacturing, education, insurance, legal and technology. The group has operated since June 2021.
The initial access section reads like a patch backlog. Affiliates exploit CVE-2024-1709, the ScreenConnect authentication bypass; CVE-2023-48788, a SQL injection in Fortinet FortiClient EMS; CVE-2025-10035, a deserialization flaw in Fortra GoAnywhere MFT; and CVE-2026-1731, a pre-authentication command injection in BeyondTrust Remote Support rated CVSS 9.8. The agencies note the operators pick up newly published exploits within 24 hours of release.
The group also buys its way in. The advisory describes payments of $100 to $1 million to initial access brokers, followed by quiet movement with PowerShell, Mimikatz and legitimate remote tools such as AnyDesk and SimpleHelp. The encryptor, gaze.exe, appends the .medusa extension to what it locks. Victims land on a leak site with a countdown timer, a 48-hour window to respond, and a $10,000 daily fee in cryptocurrency to push the clock back.
Medusa has run as a ransomware-as-a-service operation since 2023, selling the playbook to affiliates rather than running every intrusion itself. The sector list touches device manufacturers from two directions. Manufacturing appears among the victim sectors in its own right, in a year when Stryker, Medtronic, Abbott, Cook Medical and Baylor Genetics have all disclosed corporate intrusions. The healthcare targeting lands on the hospitals that run manufacturers' devices, where an encrypted network stalls imaging, pharmacy and lab operations even when no device is touched.
The four named CVEs sit in remote support, endpoint management and managed file transfer products, the same categories manufacturers depend on to service devices in the field. A ScreenConnect or BeyondTrust box operated by a field service team is part of the device attack surface, whether or not it appears in any SBOM.
The mitigation list is familiar: patch known exploited vulnerabilities first, require phishing-resistant multifactor authentication, segment networks, keep offline backups, and investigate remote access tools nobody installed on purpose. The agencies call timely patching one of the most efficient and cost-effective defenses. Medusa's 24-hour exploit adoption is what sets the deadline.