ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability
|by Alpha Team

ZeroFox Intelligence Flash Report - Fortra Discloses Critical MFT Vulnerability
Product Serial: F-2024-01-24a
TLP:CLEAR
In this flash report, ZeroFox researchers report on Fortra's disclosure of a new critical vulnerability effective its GoAnywhere Managed File Transfer Software.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On January 22, 2024, Fortra publicly disclosed a critical authentication bypass flaw in its GoAnywhere managed file transfer (MFT) software, for which a security patch has been released to end users.
- Although no active exploitation in the wild has been observed as of this writing, recent public disclosure and the publication of a proof-of-concept (PoC) suggests that attacks against unpatched systems are very likely.
- In Q1 2023, the Cl0p extortion collective successfully exploited a zero-day vulnerability in Fortra’s MFT software in what became one of the most widespread and lucrative Ransomware & Digital Extortion (R&DE) campaigns of the year.
Tags: tlp:clear, MAL Ransomware, vulnerability/exploit, threat actor