LIVE · cybersecurity feed
Live wire
ransomwarecritical

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

zeroday.news ·

A joint advisory from U.S. and Republic of Korea authorities has warned that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations. The advisory, issued on August 10, was authored by the FBI, CISA, and other U.S. government agencies, alongside the Republic of Korea’s National Police Agency (KNPA).

Gunra, which first appeared in April 2025 and is based on leaked Conti ransomware source code from 2022, developed a structured RaaS affiliate program in early 2026, advertised on dark web forums. The group has also adopted new aliases, including "Golden Community."

The FBI has observed Gunra specifically targeting two legacy Fortinet authentication bypass vulnerabilities affecting FortiOS and FortiProxy versions. CVE-2024-55591 is a critical flaw that allows a remote attacker to gain super-admin privileges through crafted requests to a Node.js websocket module. CVE-2025-24472 is a high-severity vulnerability that can allow a remote unauthenticated attacker, with prior knowledge of upstream and downstream device serial numbers, to gain super-admin privileges on a downstream device if the Security Fabric is enabled, via crafted CSF proxy requests. Patches are available for both vulnerabilities.

Following initial access, Gunra actors are adept at establishing persistence and achieving lateral movement within victim environments, often bypassing authentication protocols. In one observed instance, the group gained access to an administrator account for an SSL-VPN appliance by exploiting default credentials where account lockout controls were absent. They then established connections to an external attacker-controlled server by downloading the SSH tunneling tool OpenSSH. In another case, attackers modified authentication processing files on a corporate VDI authentication portal server to continuously bypass multi-factor authentication (MFA).

Gunra employs stealth and defense impairment techniques to hinder detection and analysis while moving across networks using stolen credentials and authentication bypass methods. These techniques include deleting system and network access logs and clearing command history. The group primarily conducts malicious activities and internal infrastructure reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone, when administrators are typically offline.

The group also focuses on exfiltrating large volumes of data from victim environments before detection, enabling a double-extortion strategy. The ransomware binary includes extensive filtering rules to target only user data, avoiding non-critical files and streamlining the collection of sensitive information. The FBI has observed Gunra actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, attackers successfully exfiltrated tens of terabytes of data by generating compressed archives of sensitive information and transferring them to the file-sharing service Mega.

Gunra's ransom demands typically begin in the tens of millions of dollars, described as "arbitrarily high." Victims are usually given five to seven days to initiate negotiations via a Tor-based portal. The group has also attempted to communicate directly with management staff at victim organizations via email. Threats of data publication on Gunra’s data leak site are made if victims fail to engage or make a payment. Victims have been observed across various critical sectors globally, including healthcare, financial services, government organizations, and critical manufacturing.

The advisory urged organizations to prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. It also recommended implementing and testing offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without ransom payment, and segmenting networks to restrict lateral movement from an initially compromised device to other systems.

ransomwarevulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.