Microsoft Connects GoAnywhere Zero-Day to Ransomware Campaigns
Originally Published 3 months ago — by The Hacker News

Microsoft links the threat group Storm-1175 to exploiting a critical deserialization vulnerability in Fortra GoAnywhere (CVE-2025-10035) to deploy Medusa ransomware, with active exploitation since September 2025, involving system compromise, lateral movement, and data exfiltration.
