Maximum severity GoAnywhere MFT flaw exploited as zero day
ID: 24c99dec-4624-5849-8807-46b9f7b9c9e2
STIX ID: report--24c99dec-4624-5849-8807-46b9f7b9c9e2
Feed Name: Bleeping Computer
A critical deserialization zero-day (CVE-2025-10035) in Fortra GoAnywhere MFT is being actively exploited to achieve unauthenticated remote command execution, create a backdoor admin account (admin-go), and deploy secondary payloads including zato_be.exe and an abused SimpleHelp binary (jwunst.exe). WatchTowr Labs reports credible evidence of exploitation dating before the vendor advisory; recommended mitigations include patching to fixed versions (7.8.4 or 7.6.3), removing public exposure of the Admin Console, and searching logs for 'SignedObject.getObject'.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
