Caitlin Condon

@catc0n.bsky.social

Adventurer. Takes a lot of photos, calls many places home. VP of research @VulnCheck. Previously vulnerability research director @Rapid7 / @metasploit.

I haven't found exploitation of Fortra's GoAnywhere MFT CVE-2025-10035 in EDR telemetry yet. Which means it is probably still rare and folks have some time to patch. Wonder how long it will stay that way. The previously exploited vulns appeared fairly quickly.

The Secret Service isn't claiming it foiled any plot targeting the UN General Assembly. Just that a big collection of SIMs (probably used for fraud) could have *potentially* disrupted NYC cell service. The SIMs were in a *35 MILE* radius of the UN. These headlines are all pretty egregiously wrong:

BildBildBild
Andy Greenberg@agreenberg.bsky.social · 11mo ago

A giant SIM farm in the NY area with 100,000 SIMs was most likely used for spam/scams and even swatting US officials—which led the feds to find and dismantle it. (Speculation it was going to be used to attack the the UN General Assembly seems like...a bit of a leap.) www.wired.com/story/sim-fa...

Last night, Fortra disclosed a critical vulnerability in their GoAnywhere MFT file transfer product. CVE-2025-10035 has a virtually identical description to CVE-2023-0669, which was exploited by ransomware crews. Unclear if this one has been exploited. Patch now. www.vulncheck.com/blog/cve-202...

CVE-2025-10035: Critical Vulnerability in Fortra GoAnywhere MFT | Blog | VulnCheck

A new critical vulnerability was disclosed in Fortra's GoAnywhere managed file transfer product, which has been targeted in the past by ransomware and extortion groups

vulncheck.com

Gen Z in Nepal burned down the parliament, burned down the homes of government officials, forced the prime minister to resign, and paraded the finance minister through the streets nearly naked.

Bild

I know NPM and SAP and probably other acronyms are on fire today, but @vulncheck.bsky.social put out a Chrome extension for #CVE and #exploit intel and it's saving me kind of a lot of tab-switching effort, so you get 🎉 🤠posts from me instead of 🗑️🔥 posts www.vulncheck.com/blog/vuln-ch...

VulnCheck Insights: CVE Context at the Hover of Your Cursor | Blog | VulnCheck

Instead of bouncing between tabs, you now get instant, current context the moment a CVE appears on your screen.

vulncheck.com