Vulnerabilities & Exploits · Ransomware

Gunra Shifts Ransomware to Perimeter Break-ins

U.S. and South Korean agencies said Gunra ransomware is actively exploiting Fortinet FortiOS/FortiProxy flaws CVE-2024-55591 and CVE-2025-24472, plus Schneider Electric PowerLogic P5 CVE-2024-5559, to get into healthcare, finance, government, and critical-infrastructure networks. The same alert says the Conti-derived group has also formalized a Dark Web affiliate program, turning a Spring 2025 brand into a broader ransomware-as-a-service operation.

The entry path matters: Gunra is not starting with phishing and endpoint malware. It is abusing exposed firewalls, VPNs, and industrial appliances on their public interfaces, where the bugs can hand over admin-level control or bypass authentication, so the first compromise can land at the perimeter or even near OT/ICS gear before any workstation is touched.

For organizations that use those devices as the front gate to internal systems, the lasting exposure is the network behind them. Once an internet-facing appliance falls, the blast radius can quickly extend from a single box to the environment it controls, with double extortion layered on top.

3 sources · Aug 12

CVE-2024-55591

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0… Known ransomware campaign use. EPSS 94% (100th percentile).

CISA federal remediation date Jan 21 · date passed

CVE-2025-24472

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: an Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through… Known ransomware campaign use. EPSS 7% (94th percentile).

CISA federal remediation date Apr 8 · date passed

Timeline

Sources

Vendor digest: Microsoft

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Gunra Shifts Ransomware to Perimeter Break-ins

More from today