Gunra Ransomware Targets Government & Critical Infrastructure Using Fortinet Exploits
What Happened – The U.S. Cybersecurity and Infrastructure Security Agency and South Korea’s National Policy Agency issued a joint advisory warning that the Gunra ransomware gang is actively exploiting two Fortinet authentication flaws (CVE‑2024‑55591, CVE‑2025‑24472) and credential‑exposure weaknesses in internet‑facing VPN/SSH gateways to compromise government and critical‑infrastructure networks. The group, derived from leaked Conti source code, now runs a ransomware‑as‑a‑service platform and is recruiting initial‑access brokers.
Why It Matters for Compliance & Audit Readiness
- Demonstrates why continuous vulnerability‑management (SOC 2 CC6.1) and evidence of timely patching are essential audit controls.
- Highlights the need for documented network‑segmentation and backup procedures (SOC 2 CC7.2) that can be presented as proof of a resilient environment.
- Provides a concrete use‑case for control‑mapping and automated evidence collection, the capability that lets you show auditors you continuously monitor and remediate high‑severity flaws.
Who Is Affected – Government agencies, public‑health bodies, healthcare providers, financial services firms, and other critical‑infrastructure operators worldwide.
Recommended Actions
- Map your vulnerability‑management process to SOC 2 CC6.1, ensuring every CVE (especially public‑facing auth bugs) is tracked, patched, and logged.
- Implement network‑segmentation controls and offline backup routines that satisfy SOC 2 CC7.2, and capture configuration snapshots as audit evidence.
- Deploy continuous‑monitoring tools that automatically collect patch‑status and segmentation proof for the Trust Center.
Source: BleepingComputer
Technical Notes
- Exploited FortiOS/FortiProxy auth flaws: CVE‑2024‑55591, CVE‑2025‑24472.
- Leveraged credential‑exposure and SSH/VPN gateway weaknesses for initial access.
- Ransomware variant runs on both Windows and Linux, with a RaaS affiliate model launched Jan 2026.
Source: BleepingComputer