On 1/22/24, Fortra published a security advisory on CVE-2024-0204, a critical authentication bypass affecting its GoAnywhere MFT secure managed file transfer product prior to version 7.4.1.
An info-stealing PyPI malware author was identified discreetly uploading malicious packages.
If you're still running a vulnerable instance then 'assume a breach'