Código HTML do Conteúdo

Post: Maximum severity GoAnywhere MFT flaw exploited as zero day - Against Invaders - Notícias de CyberSecurity para humanos.


<div> <div> <p>Hackers are actively exploiting a maximum severity vulnerability (CVE-2025-10035) in Fortra&rsquo;s GoAnywhere MFT that allows injecting commands remotely without authentication.</p> <p>The vendor disclosed the flaw<a href="https://www.bleepingcomputer.com/news/security/fortra-warns-of-max-severity-flaw-in-goanywhere-mfts-license-servlet/" rel="nofollow noopener" target="_blank">on September 18</a>, buit the company had learned about it a week earlier, and did not share any details on how it was discovered or if it was being exploited.</p> <p>CVE-2025-10035 is a deserialization vulnerability inthe License Servlet of the GoAnywhere managed file transfer software that can be leveraged to inject commands by &ldquo;an actor with a validly forged license response signature.&rdquo;</p> <p>Although Fortra&rsquo;s advisory hasn&rsquo;t been updated to include any information about the vulnerabililty being used in attacks, security researchers at WatchTowr Labs say that they received &ldquo;credible evidence&rdquo; ofFortra GoAnywhere CVE-2025-10035 being leveraged as a zero day.</p> <p>&ldquo;We have been given credible evidence of in-the-wild exploitation of Fortra GoAnywhere CVE-2025-10035 dating back to September 10, 2025,&rdquo; <a href="https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/" rel="nofollow noopener" target="_blank">reads WatchTowr&rsquo;s report</a>.</p> <p>&ldquo;That is eight days before Fortra&rsquo;s public advisory, published September 18, 2025,&rdquo; the researchers point out.</p> <p>&ldquo;This explains why Fortra later decided to publish limited IOCs, and we&rsquo;re now urging defenders to immediately change how they think about timelines and risk.&rdquo;</p> <p>WatchTowr confirmed that the analyzed data contains the stack trace related to exploitation and the creatiuon of a backdoor account:</p> <ol> <li>achievingremote command execution after exploiting the pre-auth deserialization vulnerability</li> <li>creating a backdoor admin account called<em>admin-go</em></li> <li>using the account to create a web user that enabled &ldquo;legitimate&rdquo; access</li> <li>uploadingand executingmultiple secondary payloads</li> </ol> <p>From the indicators of compromise WatchTowr published at the bottom of the report, the payloads are named &lsquo;<em>zato_be.exe</em>&lsquo; and &lsquo;<em>jwunst.exe</em>.&rsquo;</p> <p>The latter is a a legitimate binary for the remote access product SimpleHelp. In this case, it is being abused for persistent hands-on control of the compromised endpoints.</p> <p>The researchers also note that the attackers executed the &lsquo;<em>whoami/groups</em>&lsquo; command, which prints the current user account and Windows group memberships, and saved the output to a text file (<em>test.txt</em>) for exfiltration.</p> <p>This allows the threat actor to check the privileges of the compromised account and explore lateral movement opportunities within the breached environment.</p> <div> <p><img decoding="async" alt="Observed traces of exploitation" height="600" src="https://www.bleepstatic.com/images/news/u/1220909/2025/September/exploitation(1).jpg" width="472 /&gt;&lt;/div&gt; &lt;p&gt;BleepingComputer has contacted Fortra requesting a comment on WatchTowr's findings, but we have not received a response yet.&lt;/p&gt; &lt;p&gt;Given the active exploitation status for CVE-2025-10035, system administrators who haven't taken action, are recommended to upgrade to a patched version, either 7.8.4 (latest) or 7.6.3 (Sustain Release).&lt;/p&gt; &lt;p&gt;One mitigation is to remove public internet exposure for the GoAnywhere Admin Console.&lt;/p&gt; &lt;p&gt;Fortra has &lt;a href=">also recommendsthat admins inspect log files for errors containing the string&rdquo;SignedObject.getObject,&rsquo; to determine if an instance has been impacted.</p> <p><a href="https://hubs.li/Q03B5Kw_0" rel="noopener sponsored" target="_blank"><br /> <img decoding="async" alt="Picus Blue Report 2025" src="https://datalake.azaeo.com/wp-content/uploads/2025/08/blue-report-2025.jpg"><br /> </a> </p> </div> </div></div>