- CVE -2025-10035 is absorbed by the storm MFT Ranswar -1175
- Weakness allows you to perform unprotected distant code; Medusa ransomwear has deployed at least one case
- The patch was launched on September 18; More than 500 examples exposed to instant updates or mulch
Microsoft warns that the coating group has recently operates the most intense weakness found in the GOANO Manader file transfer.
Fortra recently stated that he invented and poured out the vulnerability of the referring to MFT Goano licenses, this is a tool that helps entrepreneurs and receive files safely.
The CVE-2025-10035 provided an error and maximum intensity (10/10 critic) to address a voluntary object controlled by an actor who has signed a truly false license reaction to threatening, “perhaps command injection.”
Storm -1175
Soon security researchers said Latchwaar Laboratories said the error was used as zero at the beginning of September 10. However, at the time, there was no talk about the relationship: we do not know who used the mistake for what purpose and against any business.
Microsoft has now posted a new report by pointing to the finger threat, tracking him as a storm -1175.
“Microsoft defense researchers have identified operations on several companies, strategies, strategies and methods (TTP) combined with methods, methods and methods (TTP),” Microsoft said. “
Microsoft also says this group has used weakness to infect its targets with Medusa’s deformation.
“After all, in a devoted environment, a successful deployment of Medusa Ransomower was noticed,” he summarized.
The patch was published on September 18 from the weakness, but it is safe to assume that they were not resolved. The Shadow Server Foundation says there are now more than 500 MFT Goani MFT examples, but it is unclear how many of them the patch.
The best way to protect against the attacks is to update the latest version (7.8.4) or upgrade to a strong version of the patch 7.6.3.
Those who cannot pay at this time can exclude Goani from public Internet administration, and those who suspect that they can attack, will have to check the file records for “signidbject.jetbject, chain defects”.
Through Computer

