Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

A joint advisory from U.S. and Republic of Korea authorities has warned that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations. The advisory, issued on August 10, was authored by the FBI, CISA, and other U.S. government agencies, alongside the Republic of Korea’s National Police Agency (KNPA).
Gunra, which first appeared in April 2025 and is based on leaked Conti ransomware source code from 2022, developed a structured RaaS affiliate program in early 2026, advertised on dark web forums. The group has also adopted new aliases, including "Golden Community."
The FBI has observed Gunra specifically targeting two legacy Fortinet authentication bypass vulnerabilities affecting FortiOS and FortiProxy versions. CVE-2024-55591 is a critical flaw that allows a remote attacker to gain super-admin privileges through crafted requests to a Node.js websocket module. CVE-2025-24472 is a high-severity vulnerability that can allow a remote unauthenticated attacker, with prior knowledge of upstream and downstream device serial numbers, to gain super-admin privileges on a downstream device if the Security Fabric is enabled, via crafted CSF proxy requests. Patches are available for both vulnerabilities.
Following initial access, Gunra actors are adept at establishing persistence and achieving lateral movement within victim environments, often bypassing authentication protocols. In one observed instance, the group gained access to an administrator account for an SSL-VPN appliance by exploiting default credentials where account lockout controls were absent. They then established connections to an external attacker-controlled server by downloading the SSH tunneling tool OpenSSH. In another case, attackers modified authentication processing files on a corporate VDI authentication portal server to continuously bypass multi-factor authentication (MFA).
Gunra employs stealth and defense impairment techniques to hinder detection and analysis while moving across networks using stolen credentials and authentication bypass methods. These techniques include deleting system and network access logs and clearing command history. The group primarily conducts malicious activities and internal infrastructure reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone, when administrators are typically offline.
The group also focuses on exfiltrating large volumes of data from victim environments before detection, enabling a double-extortion strategy. The ransomware binary includes extensive filtering rules to target only user data, avoiding non-critical files and streamlining the collection of sensitive information. The FBI has observed Gunra actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, attackers successfully exfiltrated tens of terabytes of data by generating compressed archives of sensitive information and transferring them to the file-sharing service Mega.
Gunra's ransom demands typically begin in the tens of millions of dollars, described as "arbitrarily high." Victims are usually given five to seven days to initiate negotiations via a Tor-based portal. The group has also attempted to communicate directly with management staff at victim organizations via email. Threats of data publication on Gunra’s data leak site are made if victims fail to engage or make a payment. Victims have been observed across various critical sectors globally, including healthcare, financial services, government organizations, and critical manufacturing.
The advisory urged organizations to prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. It also recommended implementing and testing offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment, and segmenting networks to restrict lateral movement from an initially compromised device to other systems.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed