logo

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

ID: 8c45c431-b66c-5ea8-905f-8bf0c4802b26

STIX ID: report--8c45c431-b66c-5ea8-905f-8bf0c4802b26

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-08-11

Date Updated: 2026-08-12

Author: Rob Wright

...
...

US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation leveraging known Fortinet authentication-bypass flaws (CVE-2024-55591, CVE-2025-24472) to target critical infrastructure and government organizations worldwide; Gunra's affiliates perform MFA bypass and session hijacking, delete backups and archived data, run double-extortion leaks, and the advisory urges patching internet-facing VPN/firewall appliances, implementing offline immutable backups, and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.