Months after first GoAnywhere MFT zero-day attacks, Censys still sees ~180 public admin panels
ID: 3b187ec2-4dad-5b23-bce9-f8a3674cacb4
STIX ID: report--3b187ec2-4dad-5b23-bce9-f8a3674cacb4
Feed Name: Censys Blog
**Executive Summary:** In early February 2023 a critical pre-authentication RCE (CVE-2023-0669) in Fortra's GoAnywhere MFT was actively exploited by ransomware groups (notably Clop and BlackCat) to exfiltrate data from multiple high-profile organizations; Censys observed 179 exposed admin panels as of April 25, 2023 with 55 instances likely unpatched, and recommends upgrading to GoAnywhere 7.1.2+, rotating master encryption keys, resetting credentials, reviewing logs, and removing internet exposure of admin consoles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
