Validated Containment Architectures are here. →Explore

Executive Summary

In early 2025, Medusa ransomware operators—tracked as Storm-1175—successfully exploited a critical vulnerability (CVE-2025-10035) in the Fortra GoAnywhere Managed File Transfer (MFT) platform. The attack required access to a private key, indicating either an advanced intrusion or insider compromise. Once inside, the threat actors moved laterally to deploy ransomware payloads, seizing sensitive business data and disrupting managed file transfers for impacted organizations. Multiple enterprises suffered data theft, business downtime, and reputational damage as a result.

This incident underscores an ongoing trend of targeting supply chain platforms and MFT products with ransomware via sophisticated access methods. As ransomware groups become more resourceful in exploiting zero-days and leveraging stolen keys, organizations must prioritize proactive threat detection, timely patching, and tighter access controls to counter these evolving tactics.

Why This Matters Now

This exploitation highlights the growing urgency to secure MFT and supply chain solutions against advanced ransomware actors who are actively developing and leveraging zero-day vulnerabilities. The Medusa attack demonstrates that privileged credentials and keys remain highly sought-after entry points, demanding immediate defensive focus and improved key management strategies.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers exploited CVE-2025-10035 in the Fortra GoAnywhere MFT platform, possibly leveraging a stolen private key to gain unauthorized access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, egress policy enforcement, east-west traffic controls, and inline threat detection would have limited attacker movement, surfaced anomalous behaviors, and blocked data theft and ransomware activity within the cloud environment.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline enforcement and real-time inspection would rapidly detect and alert on exploit signatures or anomalous access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based segmentation limits attacker movement and privilege expansion paths.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement is blocked or detected between workloads and services.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering and policy enforcement block unauthorized outbound channels and malware C2 connections.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Exfiltration attempts are detected and blocked via egress controls and observability.

Impact (Mitigations)

Anomalous encryption and ransomware behaviors are rapidly surfaced and contained.

Impact at a Glance

Affected Business Functions

  • File Transfer Operations
  • Data Management
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive files and credentials due to unauthorized access and data exfiltration.

Recommended Actions

  • Implement Zero Trust Segmentation to limit the blast radius of initial compromise and restrict lateral movement.
  • Enforce robust east-west traffic controls and monitor for unauthorized workload-to-workload communications.
  • Apply comprehensive egress filtering and outbound policy enforcement to detect and block data exfiltration and C2 communications.
  • Deploy inline threat detection and real-time anomaly response across cloud workloads and applications.
  • Maintain centralized multicloud visibility and control to swiftly identify and remediate cloud-based threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image