HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Gunra Ransomware Targets Government & Critical Infrastructure Using Fortinet Exploits

US and South Korean agencies warned that Gunra ransomware is exploiting Fortinet authentication CVEs and VPN credential flaws to hit government and critical‑infrastructure organizations. The threat underscores the need for SOC 2‑aligned vulnerability management and continuous audit evidence.

LiveThreat™ Intelligence · 📅 August 11, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Gunra Ransomware Targets Government & Critical Infrastructure Using Fortinet Exploits

What Happened – The U.S. Cybersecurity and Infrastructure Security Agency and South Korea’s National Policy Agency issued a joint advisory warning that the Gunra ransomware gang is actively exploiting two Fortinet authentication flaws (CVE‑2024‑55591, CVE‑2025‑24472) and credential‑exposure weaknesses in internet‑facing VPN/SSH gateways to compromise government and critical‑infrastructure networks. The group, derived from leaked Conti source code, now runs a ransomware‑as‑a‑service platform and is recruiting initial‑access brokers.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates why continuous vulnerability‑management (SOC 2 CC6.1) and evidence of timely patching are essential audit controls.
  • Highlights the need for documented network‑segmentation and backup procedures (SOC 2 CC7.2) that can be presented as proof of a resilient environment.
  • Provides a concrete use‑case for control‑mapping and automated evidence collection, the capability that lets you show auditors you continuously monitor and remediate high‑severity flaws.

Who Is Affected – Government agencies, public‑health bodies, healthcare providers, financial services firms, and other critical‑infrastructure operators worldwide.

Recommended Actions

  • Map your vulnerability‑management process to SOC 2 CC6.1, ensuring every CVE (especially public‑facing auth bugs) is tracked, patched, and logged.
  • Implement network‑segmentation controls and offline backup routines that satisfy SOC 2 CC7.2, and capture configuration snapshots as audit evidence.
  • Deploy continuous‑monitoring tools that automatically collect patch‑status and segmentation proof for the Trust Center.

Source: BleepingComputer

Technical Notes

  • Exploited FortiOS/FortiProxy auth flaws: CVE‑2024‑55591, CVE‑2025‑24472.
  • Leveraged credential‑exposure and SSH/VPN gateway weaknesses for initial access.
  • Ransomware variant runs on both Windows and Linux, with a RaaS affiliate model launched Jan 2026.

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →