Ransomware campaigns: Medusa and Clop
Medusa ransomware now 500+ victims, affiliate model, payment ranges, HHS/FBI joint advisory with triple-extortion; exploits within 24h. New scam: fake 'Ransom Busters' contacting victims before original ransomware group, offering decryption for fee. Clop ransomware exploits PTC Windchill/FlexPLM vulnerabilities (CVE-2026-12569) with custom web shell for rapid data theft; over 40 victims named including Shell, Philips, GE, Fiserv; CISA adds to KEV. Active exploitation and extortion.
Sources (4)
Updated Aug 19, 2026