A critical zero-day remote code execution (RCE) vulnerability in the GoAnywhere Managed File Transfer (MFT) software has been actively exploited by the MedusaLocker ransomware group. This vulnerability allows attackers to execute arbitrary code on vulnerable systems, leading to potential ransomware deployment and data breaches. GoAnywhere MFT is widely used by enterprises to securely transfer files, making this exploit particularly dangerous for organizations relying on this software. The MedusaLocker gang has leveraged this flaw to infiltrate networks, encrypt data, and demand ransom payments, highlighting the urgent need for patching and enhanced security measures. Security experts recommend immediate updates to the latest GoAnywhere versions and vigilant monitoring for suspicious activities to mitigate the risk posed by this zero-day exploit. This incident underscores the evolving tactics of ransomware operators and the critical importance of proactive cybersecurity defenses in protecting sensitive data and maintaining operational continuity.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 07 Oct 2025 09:45:32 +0000