CVE Tools

US and South Korea warn of Gunra ransomware targeting govt agencies

BleepingComputerBy Sergiu Gatlan

Reported exploitedFortiOSFortiProxy

Our summary

The U.S. Department of Homeland Security and South Korea’s National Policy Agency have issued a joint advisory warning that the Gunra ransomware group is actively targeting government agencies and critical infrastructure. The threat actor utilizes malware derived from the leaked Conti source code to compromise systems across various sectors, including healthcare and finance.

Investigators report that Gunra specifically exploits authentication vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet products, such as FortiOS and FortiProxy, alongside SSH misconfigurations to establish footholds. Defenders are urged to apply patches immediately, segment networks to limit lateral movement, and maintain offline backups to mitigate these expanding threats.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store