Medusa‑linked Storm‑1175 conducts fast‑moving attacks that escalate quickly to ransomware Microsoft said Storm-1175 has been deploying n-day and zero-day exploits in high-velocity campaigns and can move from initial access to data exfiltration and Medusa ransomware deployment within days, and in some cases within 24 hours. The activity heavily impacted organizations in health care, education, professional services and finance across Australia, the United Kingdom and the United States. Microsoft observed the group exploiting more than 16 vulnerabilities across products including Exchange, ScreenConnect, TeamCity, SimpleHelp, CrushFTP, SmarterMail, GoAnywhere and BeyondTrust, showing that the actor routinely rotates quickly between newly disclosed exposed services rather than relying on a single access path. After exploitation, the group has been seen creating new accounts, deploying remote monitoring and management tools, stealing credentials, and tampering with security controls before encrypting systems. That combination makes the campaign operationally important because the ransomware stage is only the final part of a broader intrusion chain. Iran‑linked actors launch widespread password spraying attacks against Microsoft 365 accounts Security researchers reported an Iran-linked password spraying campaign targeting Microsoft 365 tenants, impacting hundreds of organizations across multiple sectors. Instead of focusing on one user, the attackers systematically tried commonly used passwords across many accounts to increase the chance of success while avoiding traditional lockout thresholds. In the observed activity, the attackers targeted Microsoft 365 login endpoints, used infrastructure such as VPNs and Tor to disguise their origin, and focused on organizations in government, technology, energy and private-sector environments. Successful authentication could provide access to email, internal data and other cloud resources inside compromised tenants. This is a cloud-native identity attack because it does not rely on malware or software vulnerabilities but instead exploits weak authentication practices and inconsistent identity controls. The broader risk is that attackers can gain access with valid credentials and