Microsoft Security Blog ยท April 6, 2026

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Why it matters

Storm-1175 runs high-tempo ransomware campaigns that weaponize newly disclosed vulnerabilities for access, data theft, and Medusa deployment.

My takeaway: A good case study in attacker speed from disclosure to exploitation. AI-assisted defenders still need disciplined exposure management because the window for patching public-facing assets keeps shrinking.