Thank you, editor, for defining MFT in the penultimate paragraph.
Ding ding: Fortra rings the perfect-10 bell over latest GoAnywhere MFT bug
Budding ransomware crooks have another shot at exploiting Fortra's GoAnywhere MFT product now that a new 10/10 severity vulnerability needs patching. The vendor issued an advisory for CVE-2025-10035 on Thursday, saying successful exploitation can potentially lead to command injection. Fortra's advisory states "a …
COMMENTS
-
-
Tuesday 23rd September 2025 09:42 GMT CyberBunny
"This isn’t just about GoAnywhere. It’s about a recurring pattern: organizations relying on file transfer tools that put too much of the security burden on the customer. The lesson for CISOs is clear — resilience has to come from the platform’s design, not just from reactive patching." Patrick Spencer, VP, Kiteworks.
-
Tuesday 23rd September 2025 09:42 GMT CyberBunny
“CVE-2025-10035 is a reminder that patching alone is not enough. When admin consoles are exposed to the internet, even one flaw can lead to catastrophic exploitation. Our research shows that organisations in the mid-size ‘danger zone’ already face $3–5M breach costs — and flaws like this amplify that risk. Security has to be architectural, with hardened interfaces, sandboxed components, and layered intrusion detection built in from day one.” Patrick Spencer, VP, Kiteworks