Medusa ransomware group using zero-days to launch attacks within 24 hours of breach, Microsoft says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10035 | Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days. Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces. | 9.8 | 100% | KEV ransomware |
| moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate) | |
| CVE-2026-23760 | Unauthenticated Admin Password Reset Bypass in SmarterTools SmarterMail SmarterTools SmarterMail builds prior to 9511 contain an authentication bypass (CWE-288) in the password reset API: the force-reset-password endpoint accepts anonymous requests and, when targeting a system administrator account, never verifies the existing password or requires a reset token. An unauthenticated remote attacker simply submits a target administrator username and a new password, taking over the system administrator account with no privileges or user interaction required. Because SmarterMail's system administrator role can execute operating system commands through built-in management functionality, this escalation effectively yields SYSTEM/root-level access on the underlying mail server host, making it a path to full server and network compromise. All SmarterMail deployments running builds older than 9511 are affected, with roughly 6,000+ likely vulnerable servers observed exposed to the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-26 with known ransomware use (including Storm-1175 and Warlock activity), and public PoCs exist from WatchTowr and Huntress. Do: Immediately upgrade SmarterMail to build 9511 or later, prioritizing internet-exposed instances. Given known ransomware exploitation and the host-level access this flaw grants, check logs for anonymous calls to the force-reset-password endpoint, unexpected system administrator password changes, and signs of OS command execution or lateral movement on affected hosts. If patching is delayed, restrict or firewall access to the SmarterMail API/web interface, and follow CISA BOD 22-01 guidance for cloud-hosted deployments. | 9.3 | 96% | KEV ransomware PoC ×2 |
| moderate≈6,000+ internet-exposed SmarterMail servers |
Full article484 words · extracted from therecord.media · click to collapse
The Medusa ransomware operation is increasingly exploiting new vulnerabilities days before they are publicly disclosed, according to new research from Microsoft. Cybersecurity experts at Microsoft published an examination of activity from the group — which recently claimed responsibility for a devastating attack on the largest hospital in Mississippi and a county in northern New Jersey. Microsoft said it has been alarmed to see how effective Medusa actors are, citing multiple cases where the group can move from initial access to data exfiltration and ransomware deployment within 24 hours. Medusa actors also make a point of targeting vulnerable web-facing systems during the window between vulnerability disclosure and widespread patch adoption. “The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recent intrusions heavily impacting healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States,” Microsoft explained. Incident responders have seen Medusa hackers break into systems and immediately create new user accounts to preserve their access. While many attacks have lasted just 24 hours, Medusa incidents typically run for five to six days and rely heavily on legitimate remote management tools like ConnectWise ScreenConnect, AnyDesk and SimpleHelp. A Microsoft spokesperson told Recorded Future News that the incidents are part of a growing trend where ransomware attackers weaponize vulnerabilities almost immediately. The Microsoft blog highlights two recent bugs — CVE-2026-23760 in SmarterMail and CVE-2025-10035 in GoAnywhere Managed File Transfer — as examples of Medusa actors exploiting vulnerabilities one week before public disclosure. The Cybersecurity and Infrastructure Security Agency (CISA) previously confirmed that CVE-2026-23760 and CVE-2025-10035 have been used in ransomware attacks. Microsoft said as ransomware attackers become more adept at identifying new vulnerabilities, it will be important for organizations to understand their digital footprint before it's too late to defend against perimeter network attacks. Experts believe the Medusa operation is based in Russia due to its avoidance of targets in the Commonwealth of Independent States, its Russian-language forum activity and the use of Cyrillic script in operational tools. The group, which emerged in 2021, has repeatedly shown a willingness to target healthcare facilities and municipal governments across the U.S. The group most recently claimed attacks on New Jersey’s Passaic County and the University of Mississippi Medical Center (UMMC). The hospital fully reopened on March 2 with the help of the FBI and Department of Homeland Security. Cybersecurity experts at Symantec also recently said they saw members of Lazarus — a well-known North Korean hacking operation housed within the country’s military — deploy Medusa ransomware.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/medusa-ransomware-group-zero-days-microsoft