Story perspectives
Medusa Ransomware Targets GoAnywhere, 500 Instances Still Vulnerable
10/7/2025
1 of 1
Story summary
- Storm-1175 exploited CVE-2025-10035 in GoAnywhere MFT from Sept 10, 2025, enabling Medusa ransomware.
- Fortra issued a Sept 18 patch without warning, leaving organizations exposed.
- Security experts urge transparency on how attackers obtained necessary keys.
- More than 500 GoAnywhere instances remain exposed online. Upgrades and forensic reviews are urged. Microsoft recommends restricting external access and enabling endpoint detection.
