Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
- ID
- 13125
- Status
- summarized
- Published
- 11 Aug 2026, 10:36 PM
- Fetched
- 11 Aug 2026, 11:29 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-infrastructure/5286263
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.0
- Created
- 11 Aug 2026, 11:30 PM
- Tags
- Audience
- developerssaas_founders
What happened
US cyber agencies warn that Gunra ransomware-as-a-service is exploiting known Fortinet authentication bypass flaws (CVE-2024-55591 and CVE-2025-24472) to breach critical infrastructure. The group uses double-extortion and a Linux variant capable of 100 parallel encryption threads, targeting organizations globally.
Why it matters
If your startup or enterprise runs FortiOS or FortiProxy on internet-facing appliances, patch CVE-2024-55591 and CVE-2025-24472 immediately and enforce MFA on VPN/RDP. For most general developers and founders not managing Fortinet hardware, this requires no immediate action.
Discussion angle
How to verify if your cloud or on-prem infrastructure is exposed to known CVEs before ransomware groups exploit them.