US Indicts 17 Iranians in Global Cyber Espionage Campaign, Medusa Ransomware Hits 500 Orgs, Critical Windows Flaw Added to KEV
The U.S. has indicted 17 Iranian nationals for a vast cyber espionage operation, while the Medusa ransomware group has targeted over 500 critical infrastructure organizations, and CISA added a critical Windows vulnerability to its KEV catalog.

The U.S. Department of Justice has unsealed indictments against 17 Iranian nationals linked to the Mabna Institute, a state-sponsored hacking-for-hire firm, for orchestrating a massive global cyber espionage campaign. This operation, active since 2013, systematically targeted academic institutions, private corporations, and government agencies to steal intellectual property. While some defendants were previously indicted in 2018, the new charges expand the scope to include eight additional individuals. Investigators revealed that these hackers acted on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and other government and commercial clients, compromising approximately 80,000 professor accounts worldwide and exfiltrating over 31 terabytes of sensitive academic data valued at $3.4 billion. The campaign's reach extended to 178 universities, 53 private firms, and several government agencies, with a notable extortion attempt against HBO for $6 million.
The U.S. State Department has announced rewards of up to $10 million for information leading to the apprehension of five key defendants. The indicted individuals face multiple federal charges, including conspiracy to commit computer intrusions, wire fraud, and aggravated identity theft, carrying potential penalties of up to twenty years in prison. This prosecution underscores the U.S. government's commitment to pursuing foreign threat actors who target domestic organizations, regardless of the time elapsed since the offenses.
In parallel, a joint advisory from federal agencies warns that the Medusa ransomware syndicate has compromised over 500 critical infrastructure organizations in the United States since June 2021. This figure represents a significant increase from previous assessments, highlighting the syndicate's rapid escalation across sectors such as healthcare, manufacturing, defense, and finance. The group operates a Ransomware-as-a-Service (RaaS) model, utilizing an affiliate program and a "Medusa Blog" leak site for double extortion tactics against victims who refuse to pay.
Agencies urge organizations to implement robust defenses, including securing and patching exposed systems, restricting access from untrusted origins to remote services, and employing network segmentation to prevent lateral movement. It is crucial to distinguish this threat from other similarly named malware families, such as MedusaLocker.
Adding to the week's security concerns, CISA has added a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824, to its Known Exploited Vulnerabilities (KEV) catalog. This double-free vulnerability affects all supported versions of Windows 10, 11, and Server editions. Attackers can exploit this flaw by transmitting maliciously crafted UDP packets to vulnerable systems, potentially leading to complete network compromise.
Microsoft addressed this vulnerability in its April 2026 Patch Tuesday, but in-the-wild exploitation has prompted CISA to mandate immediate patching for all U.S. Federal Civilian Executive Branch (FCEB) agencies. While the directive targets federal networks, all enterprise network defenders are strongly advised to prioritize applying the security updates to mitigate active intrusions. For those unable to patch immediately, Microsoft recommends restricting inbound UDP ports 500 and 4500 or configuring host firewalls to accept traffic only from verified peer IP addresses.
The rapid exploitation of this IKE protocol flaw follows a pattern of recently abused Microsoft vulnerabilities, underscoring the ongoing threat landscape. CISA's inclusion of CVE-2026-33824 in its KEV catalog serves as a critical alert for defenders to prioritize remediation efforts against actively exploited threats.