AI Weekly Malaysia

Back to items Summaries

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

ID
13042
Status
summarized
Published
11 Aug 2026, 5:16 PM
Fetched
12 Aug 2026, 7:28 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
12 Aug 2026, 7:30 PM
Tags
Audience
developers

What happened

Gunra ransomware, a Conti-derived operation active since April 2025 with 51 listed victims, gains initial access by exploiting Fortinet FortiOS/FortiProxy (CVE-2025-24472) and Schneider Electric PowerLogic P5 (CVE-2024-5559) flaws, then deploys double-extortion using Salsa20/ChaCha20 encryption. The group launched a formal RaaS affiliate program in January 2026 with Windows and Linux lockers, though the Linux builds reportedly contain a catastrophic cryptographic weakness. Most victims are in South Korea, Brazil, Spain, Thailand, and Hong Kong, with targets spanning healthcare, financial services, and government sectors.

Why it matters

If your startup or employer runs Fortinet FortiOS/FortiProxy or Schneider Electric PowerLogic P5 appliances exposed to the internet, patch CVE-2025-24472 and CVE-2024-5559 immediately—these are confirmed initial-access vectors for an active ransomware campaign. The Southeast Asian victim concentration (Thailand, Hong Kong) means regional infrastructure is being targeted. Beyond patching, there is little here for builders not running these specific appliances.

Discussion angle

Whether your current infrastructure stack includes any Fortinet or Schneider Electric internet-facing appliances, and if so, whether the relevant CVEs have been patched—this is a quick operational check, not a deep technical discussion.

Top