In January 2021, Globalscape (a subsidiary of HelpSystems, now Fortra) released emergency patches to address a critical zero-day vulnerability in its Enhanced File Transfer (EFT) software.
The “Globalscape terms patched” incident is not an isolated event. Over the past 18 months, we have seen similar logic-bypass vulnerabilities in GoAnywhere MFT, MoveIT, and WS_FTP. The pattern is clear: attackers are targeting internal rule engines (often called “terms,” “policies,” or “workflows”) because they bypass network defenses. globalscape terms patched
Post-patch: Any attempt to modify term logic triggers an immediate administrative alert and rolls back the change within 2 seconds. In January 2021, Globalscape (a subsidiary of HelpSystems,
Test the Patch Manually: