CVE Tools

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Dark ReadingBy Rob Wright

Reported exploitedFortiOSGunraFortiProxy

Our summary

The FBI and South Korean authorities have issued a joint alert identifying Gunra as an active ransomware-as-a-service operation targeting critical infrastructure and government entities worldwide. The group is actively exploiting CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities in FortiOS and FortiProxy, to gain initial access to networks. In one observed attack vector, Gunra affiliates manipulated VDI portals to capture employee session data, allowing them to completely circumvent multi-factor authentication protections. Agencies advise immediate patching of affected appliances alongside the implementation of immutable offline backups and strict network segmentation.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store