Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
What happened
US cyber agencies warn that Gunra ransomware affiliates are exploiting authentication-bypass vulnerabilities in Fortinet FortiOS and FortiProxy to gain administrative access and conduct data theft plus encryption. The advisory links the actor to specific CVEs and describes a Linux variant capable of highly parallel and partial-file encryption, making compromises more damaging operationally. Watch vendor patch confirmations and whether exploit activity extends to other appliance families or unpatched estate segments
Why the category manager should care
Treat Fortinet appliance exposure as an actionable procurement gap: demand patch evidence, hardened configurations, and contractual remediation support before renewal or new buys
Key facts
- Exploits tied to Fortinet CVE references called out in the advisory
- Ransomware operates as ransomware-as-a-service with global affiliates
- Linux variant supports high-parallel encryption and partial-file encryption