Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GoAnywhere 0-Day RCE Vulnerability Exploited in the Wild to Deploy Medusa Ransomware

A critical deserialization vulnerability in GoAnywhere MFT's License Servlet, identified as CVE-2025-10035 , has been exploited by the Storm-1175 group for executing Medusa ransomware.

A critical deserialization vulnerability in GoAnywhere MFT's License Servlet, identified as CVE-2025-10035 , has been exploited by the Storm-1175 group for executing Medusa ransomware.

This vulnerability impacts GoAnywhere MFT versions up to 7.8.3, specifically in the License Servlet Admin Console. It allows threat actors to forge a license response signature, bypassing validation checks and enabling command injection into the Java process for remote code execution on exposed systems.

The flaw does not require authentication once a validly signed payload is crafted or intercepted, making exploitation straightforward on unpatched systems.

Successful exploitation allows system and user enumeration, persistence, and deployment of additional tools for lateral movement and data exfiltration.

Immediate patching is crucial. Administrators should upgrade to the versions specified in Fortra’s advisory and audit potentially compromised environments.

Microsoft Threat Intelligence has attributed active exploitation to Storm-1175, known for targeting public-facing applications.

Initial access is gained via the deserialization vulnerability in GoAnywhere MFT. Subsequently, Storm-1175 deploys RMM binaries, such as MeshAgent and SimpleHelp, into the GoAnywhere service directory, and creates JSP web shells for remote access.

Post-exploitation activities include running PowerShell commands to enumerate users, groups, domain trust relationships, and network interfaces. Command and control channels are established through RMM tools , often concealed via Cloudflare.

This vulnerability impacts GoAnywhere MFT versions up to 7.8.3, specifically in the License Servlet Admin Console.
Robert Langley · Thehackingpost

Data exfiltration is conducted using rclone, transferring stolen data to attacker-controlled cloud storage. The final stage involves encrypting victim assets with Medusa ransomware , identified by Microsoft Defender as Ransom Win32/Medusa.

Risk Factors Details

Affected Products GoAnywhere MFT License Servlet Admin Console versions below 7.8.3

Impact Command injection leading to remote code execution

Exploit Prerequisites Validly forged or intercepted license response signature

CVSS 3.1 Score 10.0 (Critical)

Upgrade immediately to the patched GoAnywhere MFT version as per Fortra's instructions.

Advertisement

Configure perimeter firewalls and proxies to block unauthorized outbound connections from GoAnywhere servers.

Enable EDR in Block Mode to allow Microsoft Defender for Endpoint to block malicious artifacts.

Deploy Attack Surface Reduction Rules to prevent common ransomware techniques, such as blocking unauthorized executable files and disabling web shell creation.

Monitor with External Attack Surface Management tools to identify unmanaged or unpatched GoAnywhere instances.

Utilize Automated Investigations and remediation features in Microsoft Defender to reduce response time and alert fatigue.

Adopting a defense-in-depth strategy that includes rapid patching, network segmentation, and advanced endpoint protection can help prevent exploitation attempts and mitigate the impact of Storm-1175 Medusa ransomware.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories