ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 543 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10035
Deserialization Flaw in Fortra GoAnywhere MFT License Servlet Enables RCE

CVE-2025-10035 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in the License Servlet of Fortra GoAnywhere Managed File Transfer (MFT). It is triggered when the servlet processes a license response carrying a validly forged signature, causing it to deserialize an arbitrary attacker-controlled object; the CVSS vector indicates the attack is network-based and requires no privileges or user interaction. Successful exploitation can lead to command injection (CWE-77), effectively giving an attacker command execution on the MFT server and access to the files and credentials that flow through it. Any organization running GoAnywhere MFT, which is commonly deployed as a central file-transfer hub, is affected, although specific affected/fixed version ranges are not provided in the available data. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2025-09-29 with known ransomware use, Microsoft attributes attacks to the Storm-1175 ransomware affiliate (Medusa, now reportedly replaced by StormEncryptor), and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Apply mitigations or patches per Fortra's vendor instructions immediately, as this is a KEV entry carrying BOD 22-01 requirements for federal agencies (patch or discontinue use if mitigations are unavailable). Because a ransomware affiliate (Storm-1175, using Medusa/StormEncryptor) is actively exploiting it, hunt for compromise: review License Servlet traffic and logs for forged license responses, check for unexpected processes or new accounts, and look for signs of lateral movement. Until patched, restrict or remove internet exposure of GoAnywhere MFT admin and license interfaces.

9.8100% KEV ransomware
  • Fortra GoAnywhere Managed File Transfer (MFT)
moderatelow thousands of internet-exposed GoAnywhere MFT instances (estimate)
CVE-2025-26399
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use.

Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server.

9.890% KEV ransomware
  • SolarWinds Web Help Desk
moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands
CVE-2025-53149
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

NVD description · AI analysis pending
7.8<1% PoC
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
Full article608 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 28, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activity 

Hacking Activities of Pro-Russian Cyber Crime Group Targeting Korean Companies

Canada dismantles TradeOgre exchange, seizes $40 million in crypto 

Scattered Spider Suspect Arrested in US

ShadowV2: An emerging DDoS for hire botnet

Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms 

Volvo Group Employee Data Stolen in Ransomware Attack

USD 439 million recovered in global financial crime operation  

Eurojust coordinates action to halt cryptocurrency fraud of over 100 million euros across Europe  

European Airport Cyberattack Linked to Obscure Ransomware, Suspect Arrested

260 suspected scammers arrested in pan-African cybercrime operation  

Ransomware attack on Ohio county impacts over 45,000 residents, employees

Malware

Brewing Trouble — Dissecting a macOS Malware Campaign  

Large-Scale Attack Targeting Macs via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware

Malware Analysis Report RayInitiator & LINE VIPER  

XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory 

Bearlyfy: The Evolution of a New Ransomware Group and Its Connection to PhantomCore

Updated BO Team Grouping Tools

Hacking

ComicForm, start: F6 analysts have studied the phishing campaigns of a new attacker  

Project Rain:L1TF  

Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver – CVE-2025-53149

Cloudflare mitigates new record-breaking 22.2 Tbps DDoS attack      

CISA Shares Lessons Learned from an Incident Response Engagement 

Cisco warns of IOS zero-day vulnerability exploited in attacks 

IMDS Abused: Hunting Rare Behaviors to Uncover Exploits  

Cisco Event Response: Continued Attacks Against Cisco Firewalls  

Technical Analysis – CVE-2025-10035 

It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) – Part 2  

ForcedLeak: AI Agent risks exposed in Salesforce AgentForce 

SVG Phishing hits Ukraine with Amatera Stealer, PureMiner  

Intelligence and Information Warfare

Mapping the Infrastructure and Malware Ecosystem of MuddyWater

Inside Palantir: The Secretive Tech Company Helping the US Government Build a Massive Web of Surveillance 

U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area

Cache of Devices Capable of Crashing Cell Network Is Found Near U.N.     

ICE unit signs new $3M contract for phone-hacking tech

Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign

Libraesva Email Security Gateway Vulnerability Exploited by Nation-State Hackers

Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors 

NCSC warns of persistent malware campaign targeting Cisco devices  

How RainyDay, Turian and a new PlugX variant abuse DLL search order hijacking

DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception    

RedNovember Targets Government, Defense, and Technology Organizations  

Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza

Cybersecurity

European airports disruption due to ransomware — EU agency

Auto giant Stellantis investigating data breach following ‘unauthorized access’  

Statement on AI and Cybersecurity

European airports still dealing with disruptions days after ransomware attack

SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw

CISA: ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices

Cyberattack on Jaguar Land Rover threatens to hit British economic growth     

Statement from the Canadian Centre for Cyber Security on malware targeting global organizations through Cisco Systems 

Brits warned as illegal robo-callers with offshored call centers fined half a million

Gcore Radar Attack Trends Q1‑Q2 2025  

Viral call-recording app Neon goes dark after exposing users’ phone numbers, call recordings, and transcripts  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182698/breaking-news/security-affairs-newsletter-round-543-by-pierluigi-paganini-international-edition.html