Critical RCE (CVE-2025-10035) in GoAnywhere MFT Used by Medusa Ransomware Group
ID: 9f3d6ce5-5754-5417-b78f-7fef5163f609
STIX ID: report--9f3d6ce5-5754-5417-b78f-7fef5163f609
Feed Name: securityonline.info
Threat Score
Microsoft observed active exploitation of a critical deserialization vulnerability (CVE-2025-10035, CVSS 10.0) in GoAnywhere MFT by the criminal group Storm-1175; attackers bypassed signature verification to achieve unauthenticated RCE, installed legitimate RMM tools for persistence, used Cloudflare tunnels for C2, exfiltrated data with Rclone, and deployed Medusa ransomware — organizations are urged to apply vendor patches and hunt for post-compromise indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
