U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

Government agencies and critical infrastructure organizations globally are being urged by U.S. federal agencies and South Korea's National Policy Agency to bolster their defenses against Gunra ransomware attacks. A joint advisory issued Monday, August 11, 2026, details that the Gunra ransomware group, which first appeared in April 2025, utilizes a variant of malware based on the Conti ransomware source code that was leaked in February 2022.
The ransomware group has been observed targeting a broad spectrum of industries, including healthcare, public health, financial services, and government entities. Initially, Gunra attacks focused on Windows environments, but by mid-2025, the actors introduced a Linux variant, expanding their campaigns to cross-platform operations. The FBI has noted instances where Gunra actors attempted to directly contact management staff at victim companies via email to solicit ransom payments, though with limited success.
To gain initial access to target networks, Gunra actors have exploited critical authentication vulnerabilities in Fortinet firewalls, specifically CVE-2024-55591 and CVE-2025-24472, affecting FortiOS and FortiProxy software. They also leverage credential exposure and Secure Shell (SSH) access control flaws in internet-facing VPN gateways to achieve remote access to victim systems.
Since January 2026, Gunra has significantly expanded its operations by launching a formal ransomware-as-a-service (RaaS) platform on dark web forums. This platform provides affiliates with a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured documentation. The group has also adopted new branding aliases, notably operating under the name "Golden Community," to support this expansion. Furthermore, Gunra is actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering them a share of the ransom profits in exchange for enterprise network access.
The U.S. and South Korean agencies recommend several defensive measures. These include promptly patching known exploited vulnerabilities in internet-facing systems, segmenting networks to restrict lateral movement, and maintaining offline backups of critical data.
This joint alert follows an earlier advisory from South Korean cybersecurity firm AhnLab, in collaboration with multiple South Korean government agencies. That previous advisory highlighted connections between the Gunra ransomware gang and the Lazarus Group, a hacking group widely believed to be state-sponsored by North Korea.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed