HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Gunra Ransomware Gang Exploits Fortinet Firewall and VPN Flaws, Bypassing MFA

Gunra ransomware operators are using legacy Fortinet firewall and VPN vulnerabilities to infiltrate critical‑infrastructure environments, sidestepping MFA. The scenario highlights the need for robust vulnerability‑management and MFA enforcement controls in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Gunra Ransomware Gang Exploits Fortinet Firewall and VPN Flaws, Bypassing MFA

What Happened — The Gunra ransomware‑as‑a‑service operation is leveraging legacy vulnerabilities in Fortinet firewalls and VPN appliances to gain footholds in critical‑infrastructure networks. By chaining these flaws with techniques that sidestep multi‑factor authentication (MFA), the gang has accelerated ransomware deployments against utilities, telecoms and other high‑value targets.

Why It Matters for Compliance & Audit Readiness

  • Unpatched network‑device vulnerabilities directly violate SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls that require timely patching and configuration management.
  • MFA bypasses expose weaknesses in CC6.2 (Logical Access Security) and demonstrate the need for continuous evidence that strong authentication is enforced and monitored.
  • Mapping these gaps to Verisq’s Control Mapping capability provides an auditable trail of remediation actions and real‑time proof of compliance.

Who Is Affected — Energy & utilities, telecommunications, and other critical‑infrastructure operators that rely on Fortinet perimeter security products.

Recommended Actions

  • Inventory all Fortinet appliances and verify firmware versions against the latest security advisories.
  • Prioritize patching of the identified CVEs (e.g., CVE‑2022‑22947, CVE‑2023‑27997) and enforce a documented patch‑management schedule.
  • Validate MFA configurations, enable adaptive authentication, and log all MFA events for continuous monitoring.
  • Map remediation steps to SOC 2 controls and capture evidence in a centralized Trust Center for audit readiness.

Source: Dark Reading

Technical Notes

  • Attack vector: exploitation of known FortiOS and FortiGate firewall vulnerabilities combined with credential‑theft techniques that neutralize MFA.
  • Data at risk: network‑level access, potential exfiltration of SCADA telemetry, and ransomware encryption of operational systems.
  • Relevant CVEs: CVE‑2022‑22947 (FortiOS API RCE), CVE‑2023‑27997 (VPN authentication bypass), among others disclosed in Fortinet security advisories.
📰 Original Source
https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →