Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
ID: 84d82be8-581b-5d8b-8866-e264f5ec3854
STIX ID: report--84d82be8-581b-5d8b-8866-e264f5ec3854
Feed Name: Infosecurity Magazine (News)
A joint US–Republic of Korea advisory warns that the Gunra ransomware-as-a-service group (also known as Golden Community) actively exploits two legacy Fortinet authentication bypass vulnerabilities to gain super-admin access, then uses authentication bypasses, credential theft, and stealthy lateral movement to exfiltrate large volumes of data (including tens of terabytes from Microsoft 365) and demand multi‑million dollar ransoms; the advisory urges patching, immutable offline backups, and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
