Close Menu
  • Home
  • Technology
  • Gaming
  • Technology
  • People’s Favorite
  • Latest Movie Review

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Top 10 Indian Social Media Apps in India

October 13, 2025

Physicists Win 2025 Nobel Prize for Groundbreaking Quantum

October 13, 2025

Microsoft Acknowledges GoAnywhere Vulnerability Exploited by Medusa Ransomware

October 8, 2025
Facebook X (Twitter) Instagram
  • Technology
  • Trending Videos
  • Phones & Tech
  • New Gadgets
Facebook X (Twitter) Instagram Pinterest Vimeo
TechyeuTechyeu
  • Home
  • Technology
  • Gaming
  • Technology
  • People’s Favorite
  • Latest Movie Review
Subscribe
TechyeuTechyeu
Home » Microsoft Acknowledges GoAnywhere Vulnerability Exploited by Medusa Ransomware
Featured

Microsoft Acknowledges GoAnywhere Vulnerability Exploited by Medusa Ransomware

TechyeuBy TechyeuOctober 8, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
“Microsoft Acknowledges GoAnywhere Vulnerability Exploited by Medusa Ransomware”
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft Confirms GoAnywhere Zero-Day Exploited by Medusa Ransomware

A newly discovered zero-day flaw in Fortra’s GoAnywhere Managed File Transfer (MFT) software has become the latest target for Medusa ransomware attackers, Microsoft confirmed this week.

The flaw, CVE-2025-10035, carries a maximum 10.0 CVSS score and stems from a deserialization weakness in GoAnywhere MFT’s License Servlet Admin Console versions up to 7.8.3. It allows attackers to remotely execute arbitrary code on unpatched servers — even without authentication in some cases — making it a prime target for ransomware operators.

According to Microsoft Threat Intelligence, a cybercrime group known as Storm-1175, a Medusa ransomware affiliate, began exploiting the flaw as early as September 11, 2025, nearly a week before vendor Fortra issued its patch on September 18, 2025.

Security researchers at WatchTowr Labs later confirmed that the flaw had been used as a zero-day, compromising several organizations before the patch was released.

“Microsoft Defender researchers identified exploitation activity in multiple organizations aligned to tactics, techniques, and procedures (TTPs) attributed to Storm-1175,” Microsoft said in its advisory while confirming WatchTowr Labs’ report.

Inside The Attack Chain (From Exploit To Encryption)

  • Initial Access: Storm-1175 exploited the GoAnywhere deserialization flaw to break into corporate systems.
  • Persistence: Installed RMM tools like SimpleHelp and MeshAgent, often disguised within GoAnywhere directories.
  • Post-Exploitation: Deployed .jsp files, ran network scans, and performed user/system reconnaissance.
  • Network Discovery: Scanned networks using Netscan and conducted user reconnaissance.
  • Lateral Movement: Used Microsoft Remote Desktop to move across systems.
  • Command & Control (C2): Set up a Cloudflare tunnel for secure communication.
  • Exfiltration: Stole data via Rclone before deploying Medusa ransomware.

Fortra Under Fire

Security experts criticized Fortra for quietly issuing a patch on September 18, 2025, without warning users of active exploitation. Benjamin Harris, CEO of WatchTowr Labs, highlighted that organizations were under silent attack since September 11, with little clarity from Fortra.

The Shadowserver Foundation reports that over 500 GoAnywhere MFT instances remain exposed online, with patch status unclear.

Read More  : 1337x Proxy List – October 2025 [ Mirror/ Proxy ] Updated

What Users Should Do

Microsoft and Fortra urge all customers to upgrade immediately and check for compromise, especially logs containing SignedObject.getObject.

  • Restrict external access to GoAnywhere Admin Consoles.
  • Run endpoint detection and response (EDR) tools in block mode.
  • Enable attack surface reduction rules.

Fortra notes that patching fixes the flaw but does not reverse previous breaches; forensic review is recommended.

Read More  : Microsoft Could Introduce a Free, Ad-Supported Tier for Xbox Cloud Gaming

Bottom Line

Organizations using GoAnywhere MFT should patch immediately, lock down internet access, and review systems for compromise. Medusa ransomware attacks highlight how trusted enterprise tools can become gateways for large-scale cyberattacks if not properly secured.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Could Introduce a Free, Ad-Supported Tier for Xbox Cloud Gaming
Next Article Physicists Win 2025 Nobel Prize for Groundbreaking Quantum
Techyeu
  • Website

Anything and everything because titles should not define us. A non-fiction lover. Aspiring to be better than yesterday.

Related Posts

Featured

Top 10 Indian Social Media Apps in India

October 13, 2025
Featured

Physicists Win 2025 Nobel Prize for Groundbreaking Quantum

October 13, 2025
Featured

Microsoft Could Introduce a Free, Ad-Supported Tier for Xbox Cloud Gaming

October 7, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

TorrentGalaxy Proxy List 2025 – Proxy/Mirror/Alternatives

September 5, 202537 Views

Mozilla Extends Firefox Windows 7, 8, And 8.1

September 6, 202517 Views

OpenAI Posts $4.3B in First-Half Revenue, Up 16%

September 30, 202513 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

Most Popular

TorrentGalaxy Proxy List 2025 – Proxy/Mirror/Alternatives

September 5, 202537 Views

Mozilla Extends Firefox Windows 7, 8, And 8.1

September 6, 202517 Views

OpenAI Posts $4.3B in First-Half Revenue, Up 16%

September 30, 202513 Views
Our Picks

Top 10 Indian Social Media Apps in India

October 13, 2025

Physicists Win 2025 Nobel Prize for Groundbreaking Quantum

October 13, 2025

Microsoft Acknowledges GoAnywhere Vulnerability Exploited by Medusa Ransomware

October 8, 2025

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Technology
  • Gaming
  • Technology
  • People’s Favorite
  • Latest Movie Review
© 2025 Techyeu. All Right Reserved.

Type above and press Enter to search. Press Esc to cancel.