Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: gunra (1 article)Clear

US and South Korea warn of Gunra ransomware exploiting Fortinet VPN flaws

A joint advisory from the FBI, CISA, the NSA, the Secret Service, and South Korean police warns that the Gunra ransomware group is exploiting known Fortinet VPN vulnerabilities to bypass multi-factor authentication and break into networks, targeting government agencies and critical infrastructure. Gunra, believed to be built on leaked Conti source code, runs a double-extortion model: it steals data before encrypting, using a custom tool to pull files from Microsoft OneDrive and SharePoint and moving large archives to a file-sharing service with utilities like RClone and 7-Zip. The final payload appends a distinct extension and drops a ransom note. The group has grown into a ransomware-as-a-service operation recruiting access brokers.

Check
Patch Fortinet VPN appliances to close the known flaws Gunra exploits, confirm multi-factor authentication cannot be bypassed on remote access, and review VPN logs for suspicious authentication.
Affected
Government and critical-infrastructure organizations running unpatched Fortinet VPNs; Gunra exploits the known flaws to bypass multi-factor authentication, steal data from cloud storage, and deploy ransomware across the network.
Fix
Patch and harden remote access, enforce phishing-resistant multi-factor authentication, monitor for mass data transfers to file-sharing services and tools like RClone, keep offline backups, and follow the advisory's indicators.