Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GoAnywhere 0-Day RCE Actively Exploited to Deliver Medusa Ransomware

A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.

A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.

On Mon, Sep 18, 2025, Fortra released an advisory concerning CVE-2025-10035, a deserialization flaw rated with a CVSS score of 10.0.

Threat actors identified as Storm-1175 have exploited this vulnerability to achieve remote code execution (RCE) on affected systems, leading to widespread compromise.

CVE-2025-10035 affects GoAnywhere MFT versions up to 7.8.3. The flaw allows an attacker to forge a license response signature, bypassing signature verification.

The attacker can send a crafted response, triggering the deserialization of arbitrary objects, resulting in command injection and full RCE.

CVE ID Vulnerability Type Affected Product & Versions CVSS Score (3.1)

CVE-2025-10035 Deserialization flaw GoAnywhere MFT License Servlet Admin Console ≤ 7.8.3 10.0

The vulnerability can be exploited without authentication when valid responses are crafted or intercepted, putting any internet-facing GoAnywhere deployment at significant risk.

A critical zero-day vulnerability in GoAnywhere MFT's License Servlet is currently being exploited to deploy Medusa ransomware.
نضال النعيم · Thehackingpost

Successful exploitation allows the attacker to execute system and user discovery commands and install additional tools for lateral movement.

Public guidance strongly recommends immediate updating to the patched GoAnywhere MFT release and reviewing license verification configurations.

Monitoring for unusual requests to the license servlet is also advised to detect exploitation attempts early.

Microsoft Threat Intelligence identified active exploitation beginning Mon, Sep 11, 2025. Storm-1175’s campaign follows a consistent multi-stage pattern:

Initial Access: Exploitation of the zero-day deserialization vulnerability in the License Servlet grants RCE. Persistence: Attackers deploy remote monitoring and management (RMM) tools—SimpleHelp and MeshAgent—within the GoAnywhere process and install web shells via .jsp files in the application directories. Discovery: Threat actors execute commands such as whoami, systeminfo, and net user to map the environment and deploy network scanning tools. Lateral Movement: RDP sessions using mstsc.exe facilitate movement between hosts. Command and Control: RMM tools establish persistent control, often using a Cloudflare tunnel to secure traffic. Exfiltration: Rclone is used to collect and transfer data from compromised networks. Ransomware Deployment: Medusa ransomware encrypts systems, demanding payment for decryption keys.

Organizations should immediately upgrade GoAnywhere MFT to the latest patched version per Fortra’s advisory.

Advertisement

Because patching does not undo prior exploitation, thorough investigation of systems suspected of compromise is essential. Restrict outbound internet access for servers to prevent malicious downloads and command-and-control communications.

Deploy endpoint detection and response (EDR) in block mode to ensure any malicious artifacts are halted, even if they bypass antivirus scans.

Enable automated investigation and remediation to allow rapid response to alerts. Turn on attack surface reduction rules to block common ransomware methods, including preventing web shell creation and restricting executable launches based on trust metrics.

Use an external attack surface management solution to discover unpatched GoAnywhere instances. Continuously monitor license servlet traffic for suspicious signature verification failures.

Finally, leverage Microsoft Defender vulnerability management and XDR capabilities to detect vulnerable devices, alert on exploitation attempts, and coordinate detection and response across the environment.

By combining rapid patching, stringent network controls, and advanced endpoint security, organizations can mitigate the risk posed by this high-severity GoAnywhere MFT vulnerability and disrupt Storm-1175’s Medusa ransomware campaigns.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories