CVE-2023-0669 is a pre-authentication command injection in Fortra GoAnywhere MFT, arising from insecure deserialisation in the License Response Servlet. An unauthenticated attacker reaching the administrative interface could run commands on the host.
Fortra has stated it was made aware of suspicious activity on some file transfer instances on 30 January 2023. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 10 February, and Fortra released a fixed version in February.
The Same Product Category, Four Months Early
This desk files this alongside 23-0601 deliberately. Managed file transfer was exploited as a zero-day by the same operators twice in one year, against a product bought for the specific purpose of moving regulated data between organisations.
The second campaign is remembered and the first one largely is not, which is a fact about attention rather than about severity. By the time MOVEit was disclosed, the pattern had already been demonstrated end to end: find the file transfer appliance, take the data, skip the encryption, extort the owner.
Extortion Without Encryption
Neither campaign needed to encrypt anything. Taking the data and threatening publication is sufficient leverage, and it removes the one part of a ransomware operation that reliably triggers detection.
The corpus filed the measurement consequence of this at 25-1217b, where the reported encryption rate fell to 50%, and at 25-1226b, where an attack halted before encryption turned out to be the wrong thing to count.
The Victim Count Is Not A Measurement
Reporting has put the number of organisations compromised through this flaw at over 130. That figure derives from the operators’ own leak-site listings, and this desk does not carry it in the record.
A leak site is an advertisement written by the seller. It lists what the seller wants listed, at the moment it suits them, and it is silent about anyone who paid.
Built on Fortra’s own published summary of its investigation and on Rapid7’s contemporaneous technical analysis of exploitation. The 30 January awareness date is Fortra’s. The attribution to Cl0p is as reported; reporting also raises the possibility of other operations exploiting the same flaw, and this desk has not assessed that. The figure of more than 130 compromised organisations appears in the body labelled as leak-site derived and is deliberately absent from the record. No indicators are reproduced. Graded high on the vulnerability and the exploitation; scope not established. Corrections: corrections@forensicpost.com.