zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability

Product Serial: F-2024-01-24a

TLP:CLEAR

In this flash report, ZeroFox researchers report on Fortra's disclosure of a new critical vulnerability effective its GoAnywhere Managed File Transfer Software.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On January 22, 2024, Fortra publicly disclosed a critical authentication bypass flaw in its GoAnywhere managed file transfer (MFT) software, for which a security patch has been released to end users.
  • Although no active exploitation in the wild has been observed as of this writing, recent public disclosure and the publication of a proof-of-concept (PoC) suggests that attacks against unpatched systems are very likely.
  • In Q1 2023, the Cl0p extortion collective successfully exploited a zero-day vulnerability in Fortra’s MFT software in what became one of the most widespread and lucrative Ransomware & Digital Extortion (R&DE) campaigns of the year.

Tags: tlp:clear, MAL Ransomware, vulnerability/exploit, threat actor