Published · 3d agoSecurity2 min read
Twenty-four hours: the patch window CISA now credits to Medusa, and what Clop did with a month
The updated federal Medusa advisory says the group weaponises newly announced exploits within a day, and sometimes moves a week before disclosure. Clop's Windchill campaign shows the cost.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The updated advisory states: "Medusa actors leverage newly announced exploits within 24 hours."
- The advisory states Medusa actors "have been observed to use exploits up to a week before public vulnerability disclosure."
- The advisory was originally published 12 March 2025 and updated on 18 August 2026 by the FBI, CISA and the U.S. Department of Health and Human Services to include information from FBI investigations as of April 2026.
- The advisory says there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advance access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate through patching.
- Medusa actors recruit initial access brokers on cybercriminal forums and marketplaces, offering payments between $100 and $1 million USD, plus the opportunity to work exclusively for Medusa.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Twenty-four hours is the figure, and it comes from the government rather than a vendor: Medusa actors "leverage newly announced exploits within 24 hours," according to the joint advisory that CISA, the FBI and HHS updated on 18 August 2026 [1][3]. The same sentence adds that they have been observed using exploits up to a week before public vulnerability disclosure [2].
What the number turns on is sourcing, not skill. The advisory states there is no indication Medusa develops its own zero-day or N-day vulnerabilities, preferring advance access to exploits from unknown sources or fast use of new announcements before victims can patch [4]. That capability is bought: Medusa pays initial access brokers between $100 and $1 million, with the higher rates for exclusivity, and most brokers work for several ransomware variants at once [5][6]. Target selection follows availability, not strategy, though healthcare has been a frequent victim [7]. The update cites Fortra GoAnywhere (CVE-2025-10035) and BeyondTrust (CVE-2026-1731), whose February 2026 publication Medusa treated as a shopping list [8][9]. The method scales: the tally rose from more than 300 victims in the March 2025 advisory to more than 500 as of April 2026 [10], roughly 200 organisations in 13 months, or about 15 a month [11].
Clop's PTC campaign is the same clock seen from the defender's side, with more slack and no better outcome. CVE-2026-12569 in Windchill and FlexPLM is an improper input validation flaw allowing remote, unauthenticated code execution [12]. CISA added it to its KEV catalog in June and the vendor warned of attacks [13]; police in Germany reportedly told organisations attacks were imminent [14]. Industry reported Clop exploitation in late July [15], roughly a month later [16]. According to ReliaQuest, Clop's web shell decrypts every credential in the Windchill keystore [17], which is why late patching does not close the incident. Clop has named more than 40 organisations, publishing full names since 12 August [18], with claimed hauls of 1 GB to several terabytes [19].
Watch GE, removed from the leak site, which SecurityWeek notes may indicate payment or renewed negotiation [20], and watch whether the next KEV entry gets a month of grace or a day.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The updated advisory states: "Medusa actors leverage newly announced exploits within 24 hours."
- [2]
The advisory states Medusa actors "have been observed to use exploits up to a week before public vulnerability disclosure."
- [3]
The advisory was originally published 12 March 2025 and updated on 18 August 2026 by the FBI, CISA and the U.S. Department of Health and Human Services to include information from FBI investigations as of April 2026.
ReportedView cited source - [4]
The advisory says there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advance access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate through patching.
- [5]
Medusa actors recruit initial access brokers on cybercriminal forums and marketplaces, offering payments between $100 and $1 million USD, plus the opportunity to work exclusively for Medusa.
ReportedView cited source - [6]
Most initial access brokers appear willing to work for multiple ransomware variants at the same time, according to the advisory.
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.com3d agoCl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign - SecurityWeek
- cisa.gov3d ago#StopRansomware: Medusa Ransomware | CISA



