Bottom line: The Medusa ransomware campaign has been updated to reflect the FBI, CISA, and HHS's enhanced understanding of the attack tools and exploited vulnerabilities used by the attackers.
What's happening: The attackers exploited vulnerabilities in SolarWinds Orion, Microsoft Exchange, and Log4j 2, with the FBI identifying 1,300 compromised U.S. government networks and 100,000 compromised non-U.S. government networks. The attackers used the RaaS affiliate model, which allowed them to distribute the ransomware through compromised third-party software updates.
What to do: The FBI and CISA recommend that organizations implement the following controls: (1) patch SolarWinds Orion and Microsoft Exchange, and (2) monitor for Log4j 2 vulnerabilities and update to the latest version.