#Fortra
Exciting news: Zero-Point Security has joined Fortra and will work alongside the @cobaltstrike.bsky.social, @outflank.bsky.social, and @coreimpact.bsky.social teams to develop the next generation of offensive security training! Get more details on the blog www.cobaltstrike.com/blog/new-mou...
New Mouse in the House: Zero-Point Security Training Joins the Fortra Family
Fortra has acquired Zero-Point Security, and Daniel Duggan (RastaMouse) is joining the team to build out the next generation of offensive security training.
www.cobaltstrike.com
April 2, 2026 at 2:13 PM
Fortra doing a victory lap claiming they've cut illicit Cobalt Strike usage by 80% is one thing.

CTI analysts uncritically parroting this ridiculous claim is quite another. Cobalt Strike usage is down because EDRs got better at identifying it specifically. Fortra is AT BEST a minor contributor here
March 10, 2025 at 1:57 PM
nanodump : The swiss army knife of LSASS dumping : github.com/fortra/nanod...
February 25, 2025 at 1:13 PM
Fortra has released security updates to patch a maximum severity vulnerability in GoAnywhere MFT's License Servlet that can be exploited in command injection attacks.
Fortra warns of max severity flaw in GoAnywhere MFT’s License Servlet
Fortra has released security updates to patch a maximum severity vulnerability in GoAnywhere MFT's License Servlet that can be exploited in command injection attacks.
www.bleepingcomputer.com
September 19, 2025 at 2:21 PM
Oh, the irony... AI companies, developing some of the most sophisticated programs the world has ever seen, are making such elementary security mistakes...

Read more in my article on the Fortra blog: www.fortra.com/blog/ai-comp...
Leading AI Companies Accidentally Leak Their Passwords and Digital Keys on GitHub - What You Need to Know
Many of the world's top artificial intelligence companies are accidentally publishing their passwords and digital keys on GitHub.
www.fortra.com
November 12, 2025 at 3:06 PM
I hope Fortra legal don't come after me for this one. I just couldn't resist.
November 24, 2025 at 9:50 PM
블루 스카이 - Argus C3 / Fortra 160
November 4, 2023 at 8:56 AM
Per Fortra, the number of unauthorized Cobalt Strike copies observed in the wild has decreased by 80% over the past two years: www.cobaltstrike.com/blog/update-...

This doesn't line up with the recent Recorded Future report which found CS was up 65%: www.recordedfuture.com/research/202...
Update: Stopping Cybercriminals from Abusing Cobalt Strike | Cobalt Strike
Updates on the joint efforts of Microsoft’s Digital Crimes Unit (DCU), Fortra, and Health-ISAC to combat the use of unauthorized, legacy copies of Cobalt Strike
www.cobaltstrike.com
March 8, 2025 at 9:30 PM
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.

Find out what you need to know about it in my article on the Fortra blog.
CRPx0 Ransomware: What You Need to Know | Fortra
Learn how CRPx0 ransomware works, how it spreads through ClickFix attacks, and what organizations can do to defend against ransomware threats.
www.fortra.com
September 9, 2026 at 8:44 AM
The S is for Security. How to use WinRMS as a solid NTLM relay target, and why it’s less secure than WinRM over HTTP.

writeup: sensepost.com/blog/2025/is...

PR to impacket:
github.com/fortra/impac...

Demo: youtu.be/3mG2Ouu3Umk
WinRMS Relaying
YouTube video by Sense Post
youtu.be
April 14, 2025 at 4:40 PM
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has bee…
#hackernews #microsoft #ml
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on a suspicious HTML and JavaScript attachment delivered by email, supporting DNS data, and the second-stage phishing page. Researchers said the campaign relied on business-themed lures, including secure documents, remittance services, automated billing, and payment requests. Opening the …
www.helpnetsecurity.com
June 27, 2026 at 3:01 AM
Fortra Acquires Lookout Cloud Security

Fortra today announced the acquisition of Lookout’s Cloud Security business featuring their Security Service Edge (SSE) solution. Based in Boston, Massachusetts, Lookout’s Cloud Security solution features Cloud Application Security Broker (CASB), Zero Trust…
Fortra Acquires Lookout Cloud Security
Fortra today announced the acquisition of Lookout’s Cloud Security business featuring their Security Service Edge (SSE) solution. Based in Boston, Massachusetts, Lookout’s Cloud Security solution features Cloud Application Security Broker (CASB), Zero Trust Network Access (ZTNA) and Secure Web Gateway (SWG) among other critical security solutions. In addition, with this acquisition, Fortra now offers a complete Data Security Posture Management (DSPM) solution.
itnerd.blog
May 12, 2025 at 1:54 PM
까페 고양이

Zenit TTL - Carl Zeiss Jena f/2.8 Tessar + Fortra 400
November 4, 2023 at 8:57 AM
Despite their name, there is nothing polite or refined about The Gentlemen ransomware group. Learn more about them in my article on the Fortra blog: www.fortra.com/blog/gentlem...
July 2, 2026 at 5:01 PM
Hackers are exploiting a recently patched vulnerability in Fortra GoAnywhere MFT file transfer servers. According to WatchTowr Labs, the attacks started a week after patches were release: labs.watchtowr.com/it-is-bad-ex...
It Is Bad (Exploitation of Fortra GoAnywhere MFT CVE-2025-10035) - Part 2
We’re back, just over 24 hours later, to share our evolving understanding of CVE-2025-10035. Thanks to everyone who reached out after Part 1, and especially to the individual who shared credible inte...
labs.watchtowr.com
September 28, 2025 at 2:07 PM
A relatively new strain of ransomware, SafePay, is said by researchers to be responsible for more attacks than any other in the last month.

Learn more about it, and how it is different from other ransomware, in my article on the Fortra blog:

www.fortra.com/blog/safepay...
SafePay Ransomware: What You Need To Know
SafePay breaks the mold by rejecting RaaS. Discover how this ransomware group operates and why it’s gaining ground fast.
www.fortra.com
June 27, 2025 at 11:00 AM
Today concludes my first proper week at Fortra. Here's a very public shoutout to all the teams who made me feel welcome, particularly the @cobaltstrike.bsky.social and @outflank.bsky.social guys!
April 17, 2026 at 6:22 PM
We're so pleased that Fortra is a sponsor for Hack Glasgow 2026!

Fortra delivers AI-amplified cyber security solutions that help organisations use and protect data with confidence. Powered by purpose-built AI, highly unique data sources and intelligence, and modular delivery, [...]
August 6, 2026 at 8:01 AM
We're so pleased to announce that Fortra is a sponsor for Hack Glasgow 2026!

Fortra delivers AI-amplified cyber security solutions that help organisations use and protect data with confidence. Powered by purpose-built AI, highly unique data sources and intelligence, and modular delivery, [...]
July 23, 2026 at 8:15 AM
Dark web analysts at infosec software vendor Fortra have discovered an extortion crew named Ox Thief that threatened to contact Edward Snowden if a victim didn’t pay to protect its data.
Extortion crew to victim: Pay or we tell ... Edward Snowden?
: Don't laugh. This kind of warning shows crims are getting desperate
www.theregister.com
March 19, 2025 at 4:47 PM
Microsoft blames Medusa ransomware affiliates for GoAnywhere exploits while Fortra keeps head buried
Microsoft blames Medusa ransomware affiliates for GoAnywhere exploits while Fortra keeps head buried
You can't find anything bad if you don't look, right? Medusa ransomware affiliates are among those exploiting a maximum-severity bug in Fortra's GoAnywhere managed file transfer (MFT) product, according to Microsoft Threat Intelligence.…
dlvr.it
October 6, 2025 at 11:19 PM
-PoC published for unpatched WDS bug
-Digigram PYKO-OUT Digigrams don't require authentication
-Citrix bug PoC released
-IXON VPN vulnerabilities
-Fortra security updates
-Iraian APT lurked 2 years inside Middle East CNI
-Cisco releases an open-weight LLM for cybersecurity
May 5, 2025 at 11:00 AM
Kiteworks told customers worldwide to shut down servers over a possible zero-day - no breach confirmed yet. https://intel.threadlinqs.com/threat/TL-2026-2670 #ThreatIntel #Clop #Fortra #Kiteworks
September 26, 2026 at 11:56 PM
New Crossplane function-pythonic looks good: github.com/fortra/funct...

def compose(self):
vpc = self.resources.vpc('ec2.aws.crossplane.io/v1beta1', 'VPC')
vpc.spec.forProvider.region = self.spec.region
vpc.spec.forProvider.cidrBlock = self.spec.cidr
GitHub - fortra/function-pythonic: Python based Crossplane Function providing a clean and elegant syntax for writing Crossplane Compositions.
Python based Crossplane Function providing a clean and elegant syntax for writing Crossplane Compositions. - fortra/function-pythonic
github.com
August 5, 2025 at 8:31 AM
Neuer Therapieansatz bei #MultipleSklerose auf dem Weg in die klinische Anwendung: Projektförderung über 1,1 Mio. Euro durch die ForTra gGmbH für #Forschungstransfer der Else Kröner-Fresenius-Stiftung (ForTra) ermöglicht Weiterentwicklung ...
weiterlesen
September 1, 2026 at 7:15 AM