Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
ID: 8c45c431-b66c-5ea8-905f-8bf0c4802b26
STIX ID: report--8c45c431-b66c-5ea8-905f-8bf0c4802b26
Feed Name: Dark Reading
US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation leveraging known Fortinet authentication-bypass flaws (CVE-2024-55591, CVE-2025-24472) to target critical infrastructure and government organizations worldwide; Gunra's affiliates perform MFA bypass and session hijacking, delete backups and archived data, run double-extortion leaks, and the advisory urges patching internet-facing VPN/firewall appliances, implementing offline immutable backups, and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
