Exploitation observed; activity peaked at 4 mentions and remains active
Immediate actions
Patch fortra goanywhere_managed_file_transfer systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-20. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2 #CVE202510035#GoAnywhereMFT#InTheWildExploitation#SecurityTransparency#BackdoorAccount https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/
Post summary
The tweet signals that CVE‑2025‑10035 in Fortra GoAnywhere MFT is being exploited in the wild, and it links to an article that likely contains PoC details.
Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035) #GoAnywhereMFT#CVE202510035#Deserialization#AuthBypass#PreAuthRCE https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/
Post summary
The tweet announces a pre-auth remote code execution vulnerability in Fortra GoAnywhere (CVE‑2025‑10035), highlighting deserialization and authentication bypass, and links to a detailed article.
LOOK BACK: Fortra patched a GoAnywhere deserialization bug in 2023 by wrapping it in three checks. One of them whitelisted SignedObject, whose getObject() deserializes again. CVE-2025-10035 was that same sink, reopened, and Medusa ransomware got there first. https://t.co/XmFDwd1O2j
Post summary
The GoAnywhere deserialization flaw CVE‑2025‑10035, re‑opened by an earlier patch oversight, was exploited by Medusa ransomware in the wild; the vulnerability details and patch information are present.
Storm-1175 exploits GoAnywhere MFT flaw CVE-2025-10035 in Medusa attacks, allowing easy remote code execution via License Servlet bug. A cybercrime group, tracked as Storm-1175, has been actively exploiting a maximum se... https://f.mtr.cool/yybuznoyhy
Post summary
Storm‑1175 is actively exploiting CVE‑2025‑10035 in GoAnywhere MFT, leveraging a License Servlet bug to achieve remote code execution. No mitigation or PoC details are disclosed.
Hidden Cost of MFT Vulnerabilities: Why CVE-2025-10035 Demands a New Security Playbook https://www.itsecurityguru.org/2025/10/13/hidden-cost-of-mft-vulnerabilities-why-cve-2025-10035-demands-a-new-security-playbook/ @Kiteworks
Post summary
The passage only references a CVE number in a headline, providing no technical, exploit, or mitigation details.
TRC analysis shows Medusa ransomware actors are rapidly exploiting CVE-2025-10035 and CVE-2026-23760 for initial access, then using RDP and remote management tools for lateral movement. Runtime segmentation helps limit blast radius once attackers pivot internally. #Ransomware
🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/medusa-ransomware-cisa-advisory-2026
Post summary
The post confirms that Medusa ransomware actors are actively exploiting CVE-2025-10035 and CVE-2026-23760 for initial access, then leveraging RDP and management tools for lateral movement.
Fortra on Thursday revealed the results of its investigation into CVE-2025-10035, a critical security flaw in GoAnywhere Managed File Transfer (MFT) that's assessed to have come under active exploitation since at le... https://f.mtr.cool/ykicdycxgg
Post summary
Fortra reports that CVE-2025-10035 in GoAnywhere Managed File Transfer is being actively exploited, but does not provide specific exploit details or remediation steps.
Full Look Back: how the 2023 fix created the 2025 bug, and the question three security firms couldn't answer, namely how attackers got the private signing key. https://cvebrief.com/cve/CVE-2025-10035/ https://t.co/ufbzjQRZJB
Post summary
The tweet only references a CVE with a brief description and a link, but does not provide PoC, exploitation details, patch info, or technical specifics.
https://naver.me/5su9GoRg
마이크로소프트(MS) 위협 인텔리전스 팀의 최신 조사 결과에 따르면, 이들은 보안 패치가 배포되기 전인 취약점 ‘CVE-2025-10035’ 등을 악용해 시스템을 장악한 것으로 확인됐다. 지난 2023년을 기점으로 MS 익스체인지(Exchange) 서버 등을 포함해 16개 이상의 심각한 보안
Post summary
The article confirms that CVE-2025-10035 was actively exploited against Microsoft Exchange before a patch became available.
THREAT ALERT: Storm-1175 Blitz
China-linked group weaponizing zero-days in SmarterMail (CVE-2026-23760) & GoAnywhere (CVE-2025-10035) for Medusa Ransomware.
⏱️ Speed: <24hrs to encrypt 🎯 Target: Edge assets (VPN/Mail) 🛡️ Action: Patch NOW
#CyberSecurity#ZeroDay#Storm1175
Post summary
The alert warns that Storm-1175 is weaponizing zero‑day vulnerabilities (CVE‑2026‑23760 and CVE‑2025‑10035) targeting SmarterMail and GoAnywhere, urging immediate patching to prevent potential Medusa ransomware attacks.
Storm-1175 exploited zero-day vulnerabilities CVE-2025-10035 and CVE-2026-23760 to deploy Medusa ransomware within 24 hours of initial compromise. The China-based group rapidly escalated privileges, moved laterally through credential theft, and exfiltrated data before encryption. Runtime segmentation can limit blast radius during such high-tempo operations. #ZeroDay#Ransomware
🔗 Full breakdown: https://aviatrix.ai/threat-research-center/storm-1175-medusa-ransomware-zero-day-attacks-2026
Post summary
Storm‑1175 used newly discovered CVEs to quickly deploy Medusa ransomware, demonstrating active exploitation, while recommending runtime segmentation as a mitigation.
🚨 Threat Alert: Medusa ransomware campaigns (Storm-1175 / Medusa affiliates)
📅 Date: 2026-04-06
📆 Timeline: Medusa RaaS tracked since 2023; Storm-1175 rapidly weaponized N-days and multiple zero-days (e.g., CVE-2026-23760 SmarterMail, CVE-2025-10035 GoAnywhere MFT) across 2025–2026. Microsoft published Storm-1175 analysis 2026-04-06; Symantec/Broadcom reported Lazarus-linked Medusa use in Feb 2026.
📍 Location: United States (MS, NJ and other states); activity also observed impacting organizations in the United Kingdom and Australia
📌 Attribution: Primary: Microsoft tracks actor as Storm-1175 (financially motivated affiliates using Medusa). Additional reporting links some Medusa deployments to Lazarus‑linked actors. Confidence: medium — Medusa is a RaaS used by multiple affiliate sets; single origin not definitive.
📝 Summary:
Microsoft and other vendors report high-tempo Medusa ransomware campaigns that weaponize zero-day and recently disclosed (N-day) vulnerabilities to compromise internet‑facing systems, rapidly exfiltrate data, and deploy Medusa. Intrusions can progress from initial access to exfiltration and encryption within 24 hours; typical dwell ~5–6 days. Recent victims include healthcare, municipal, education, professional services, and finance.
⚔️ Attack Details:
- Attack Type: Ransomware (Medusa) leveraging zero-day / recently‑disclosed vulnerability exploitation and human‑operated intrusion techniques
- Target: Healthcare (e.g., University of Mississippi Medical Center), municipal governments (Passaic County, NJ), education, professional services, finance; internet‑facing services and administrative systems
📈 Impact:
Data exfiltration (double‑extortion), system encryption, operational disruption (hospital impact, county phone outages), rapid full compromise in some incidents. Typical 5–6 day campaigns; higher remediation/recovery costs. Example ransom indicator: observed average ~ $260,000 in some cases (Symantec, Feb 2026).
🔗 Related Resources:
- https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/
- https://therecord.media/medusa-ransomware-group-zero-days-microsoft
- https://therecord.media/medusa-ransomware-mississippi-cyber
- https://therecord.media/new-jersey-county-says-malware-attack-took-down-phones
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
- https://www.halcyon.ai/threat-group/medusa
- https://www.broadcom.com/support/security-center/protection-bulletin/medusa-ransomware-distributed-by-the-lazarus-threat-group
- https://thehackernews.com/2026/02/lazarus-group-uses-medusa-ransomware-in.html
🛡️ Recommended Actions:
- Prioritize patching of internet‑facing systems; accelerate N-day/zero-day remediation.
- Inventory and reduce public attack surface; place web‑facing services behind WAFs/reverse proxies.
- Enforce MFA and least privilege for admin and RMM accounts; rotate/reset credentials if compromise suspected.
- Restrict, harden, and monitor RMM/remote‑access tools (ConnectWise ScreenConnect, AnyDesk, SimpleHelp); require MFA.
- Enable tamper protection and EDR/XDR; apply attack‑surface reduction (block LSASS dumping, block PsExec/WMI process chains).
- Monitor for anomalous exfiltration (Rclone, Bandizip) and cloud uploads; log and alert on new admin accounts and firewall rule changes.
- Segment networks, disable unused RDP, and isolate critical systems from web tiers.
- Maintain offline, immutable backups and test recovery; implement IR playbooks for rapid containment.
🫨 Attack Vectors:
- T1190 - Exploit Public-Facing Application (weaponized N-day/zero-day; web shells)
- T1136 - Create Account (new local/admin accounts for persistence)
- T1021 / T1219 - Remote Services / Remote Access Tools (ConnectWise ScreenConnect, AnyDesk, SimpleHelp)
- T1078 - Valid Accounts (compromised/legitimate credentials)
- T1003 - OS Credential Dumping (LSASS dumping, Mimikatz)
- T1041 - Exfiltration Over C2 Channel (Rclone, Bandizip)
- T1486 - Data Encrypted for Impact (Medusa deployment)
- T1566/T1059 - Living‑off‑the‑land and scripted execution (PowerShell, PsExec, Impacket)
🏷 Tags: #ransomware#Medusa#Storm-1175 #zero-day #exploitation#healthcare#municipal#remote-access #data-exfiltration #CISA#Microsoft#Lazarus#Cybersecurity
Post summary
The alert details a real‑world Medusa ransomware campaign exploiting zero‑day and recently disclosed vulnerabilities across multiple sectors, with active attacks reported and clear patching recommendations.
🚨 Threat Alert: Microsoft links Medusa ransomware affiliate to zero-day attacks (Storm-1175)
📅 Date: 2026-04-06 (Microsoft publication)
📆 Timeline: Active since at least 2023; 2024–2026 saw multiple n-day exploitations and exploit chaining. CVE-2025-10035 (GoAnywhere) and CVE-2026-23760 (SmarterMail) were reportedly exploited ~1 week before public disclosure. Microsoft reports rapid kill‑chains (initial access → exfiltration/encryption within days, sometimes ≤24h).
📍 Location: Australia, United Kingdom, United States (observed)
📌 Attribution: Storm-1175 — China‑based financially motivated cybercrime group; Medusa ransomware affiliate (Microsoft).
📝 Summary:
Microsoft Threat Intelligence links high‑velocity Medusa operations to Storm‑1175, an affiliate that quickly weaponizes n‑day and zero‑day flaws in internet‑facing apps to gain access, chain exploits, persist, steal credentials, disable security controls, exfiltrate with tools like Rclone/Bandizip, and deploy Medusa ransomware. Microsoft documents exploitation across numerous CVEs (incl. CVE‑2025‑10035, CVE‑2026‑23760) and use of RMM, living‑off‑the‑land binaries, web shells and PDQ Deployer for distribution. Note: partner/CISA claims (e.g., “300+ critical infrastructure orgs impacted”) are cited by partners and not independently validated here.
⚔️ Attack Details:
- Attack Type: Ransomware (Medusa) leveraging zero-day and n-day exploitation
- Target: Healthcare; education; professional services; finance; critical infrastructure organizations (partner reporting indicates 300+ impacted in prior campaigns)
📈 Impact:
Unauthorized access to internet‑facing systems, credential theft, rapid lateral movement and persistence, security tampering (disabling AV/adding exclusions), large‑scale data exfiltration (Rclone/Bandizip) and widespread file encryption via Medusa causing operational disruption and potential data leaks. Partner reporting attributes incidents affecting 300+ critical‑infrastructure orgs in the U.S.; no consolidated public financial loss figure.
🔗 Related Resources:
- https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/
- https://www.bleepingcomputer.com/news/security/microsoft-links-medusa-ransomware-affiliate-to-zero-day-attacks/
- https://nvd.nist.gov/vuln/detail/CVE-2025-10035
- https://nvd.nist.gov/vuln/detail/CVE-2026-23760
- https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-300-critical-infrastructure-orgs/
🛡️ Recommended Actions:
- Patch internet‑facing systems immediately; prioritize CVEs with public exploit activity.
- Isolate/limit web‑facing assets (WAF, reverse proxy, DMZ); use attack‑surface monitoring.
- Enforce MFA and least privilege; remove shared/local admin creds.
- Harden RMM: allow only approved RMM with MFA and strict controls.
- Enable tamper protection, attack‑surface reduction rules, Credential Guard, and EDR with automatic disruption.
- Monitor for Rclone/Bandizip, PDQ/PSExec/Impacket usage, web shells, unusual account creation and credential dumping.
- Maintain offline, tested backups and segmented restore paths.
- Hunt for IOCs, hashes and C2 indicators from Microsoft/CISA guidance; follow incident response playbooks if compromise confirmed.
🫨 Attack Vectors:
- T1190 - Exploit Public-Facing Application (zero-day and n-day exploitation; examples: CVE-2025-10035, CVE-2026-23760, multiple others since 2023)
- T1505.003 (Web Shell) / Web shell deployment for initial foothold and persistence
- T1136 - Create Account (creating new local/admin accounts for persistence)
- T1078 - Valid Accounts (use of stolen or created accounts for access and lateral movement)
- T1021 - Remote Services (use of RMM tools, AnyDesk, ConnectWise ScreenConnect, RDP tunnels for lateral movement and persistence)
- T1003 - Credential Dumping (LSASS, NTDS.dit, use of Mimikatz, Veeam password recovery)
- T1562 - Impair Defenses (disabling Microsoft Defender, modifying AV exclusions, tamper actions)
- T1041 - Exfiltration Over C2 Channel / Use of Rclone and Bandizip for large-scale exfiltration
- T1486 - Data Encrypted for Impact (Medusa ransomware deployment)
- T1569.002 / T1059 - Windows Command Shell / PsExec and living-off-the-land binaries for remote execution and lateral movement (PDQ Deployer, PsExec, Impacket)
🏷 Tags: #Medusa#Storm-1175 #ransomware#zero-day #n-day #exploits#cybercrime#healthcare#critical-infrastructure #SmarterMail#GoAnywhere#Cybersecurity
Post summary
Microsoft’s Threat Intelligence report details that Medusa ransomware affiliates have been exploiting CVE‑2025‑10035 and CVE‑2026‑23760 in the wild, with rapid kill‑chains and widespread damage, and urges immediate patching.
BREAKING: Microsoft links China-based Storm-1175 to Medusa ransomware campaigns exploiting 16+ vulns including CVE-2025-10035 and CVE-2026-23760, hitting 300+ critical infrastructure orgs.
https://threatcluster.io/cluster/storm-1175-exploits-multiple-vulnerabilities-in-medusa-ranso-4c24eb79
Post summary
The report highlights that the Storm‑1175/Medusa ransomware campaigns are actively exploiting multiple CVEs, impacting over 300 critical infrastructure organizations, but offers no PoC, exploit code, or mitigation details.
The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware https://ift.tt/pD1PeIb
The post The 24-Hour Blitz: Storm-1175 Weaponizes Zero-Days for High-Velocity Ransomware appeared first on Daily CyberSecurity.
Related posts:
Critical RCE (CVE-2025-10035…
Post summary
The article announces that the CVE‑2025‑10035 RCE has been weaponized by the Storm‑1175 ransomware campaign, but it provides no proof‑of‑concept, patch details, or evidence of active exploitation.