Drooid Logo
Back to today’s briefing

Story perspectives

Medusa Ransomware Targets GoAnywhere, 500 Instances Still Vulnerable

10/7/2025

24 2 Full Breakdown

1 of 1

Story summary
  • Storm-1175 exploited CVE-2025-10035 in GoAnywhere MFT from Sept 10, 2025, enabling Medusa ransomware.
  • Fortra issued a Sept 18 patch without warning, leaving organizations exposed.
  • Security experts urge transparency on how attackers obtained necessary keys.
  • More than 500 GoAnywhere instances remain exposed online. Upgrades and forensic reviews are urged. Microsoft recommends restricting external access and enabling endpoint detection.