logo

Microsoft: Critical GoAnywhere Bug Exploited in Medusa Ransomware Campaign

ID: 202fa38e-0669-5cca-b923-00b98be25c35

STIX ID: report--202fa38e-0669-5cca-b923-00b98be25c35

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2025-10-07

Date Updated: 2026-04-22

...
...

Microsoft warns of active exploitation of CVE-2025-10035, a critical deserialization flaw in Fortra GoAnywhere MFT (CVSS 10.0) that can bypass license signature verification and enable arbitrary object deserialization, leading to command injection and remote code execution. Observed exploitation by Storm-1175 involved use of legitimate RMM tools (SimpleHelp, MeshAgent), network discovery, lateral movement via mstsc.exe, Cloudflare tunnels for C2, Rclone for exfiltration, and final deployment of Medusa ransomware; Fortra released a patch but hundreds of GoAnywhere instances remain internet-exposed, prompting urgent mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.