Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure

https://image.theregister.com/261470.jpg?imageId=261470&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Newly minted RaaS crew breaks in through using internet-facing kit via known Fortinet flaws, then steals and scrambles data

US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks.

Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwide.

Targets have included healthcare, financial services, government, professional services, nonprofits, and other critical infrastructure organizations.

The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet's FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.

Once inside, Gunra affiliates follow the now-familiar double-extortion playbook: steal data, encrypt systems, and demand payment for a decryptor and a promise not to publish the haul.

Negotiations take place...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE