Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
CISA and partners say Gunra affiliates are walking into Fortinet holes and ransoming hospitals and agencies.
Summary
- US agencies including CISA, FBI, NSA, and Secret Service warned that Gunra ransomware affiliates are hitting critical infrastructure.
- Attackers exploit known Fortinet FortiOS/FortiProxy authentication bypass bugs, including CVE-2024-55591 and CVE-2025-24472.
- Gunra operates as ransomware-as-a-service with double extortion: steal, encrypt, then ransom on a Tor portal.
- Targets already include healthcare, finance, government, and other critical sectors in the US and abroad.
- Victims are typically given five to seven days before stolen data is threatened with publication.
Commentary
Known bugs on internet-facing firewalls are not bad luck. They are unpaid homework by operators who guard real life.
Critical infrastructure is a China-and-crime problem set. Patch, segment, and prosecute. Do not write another awareness pamphlet.
A country that cannot keep hospitals online will not keep a border or a fleet online either.
Discussion
Why are known Fortinet bugs still feeding ransomware?
soc_night
If CVE is old and the firewall is public, that is negligence with lives attached.
midwest_vet
Hospitals and water plants are war targets even when the actor is a crew.
campus_take
Stop blaming victims. Vendors should be liable only.
rule_first
Vendors ship patches. Operators must apply them. Both can be held accountable.
tokyo_ally
Japan's plants face the same RaaS economy. Shared intel, faster patch SLAs.
aid_fan
Fund global cyber NGOs with USAID money.
docket_rat
NGOs do not patch Fortinet. Network owners and FBI tasking do.
border_dad
Digital borders are borders. Leave them open and criminals walk in.
press_clip
Register relayed the advisory. Ask which agencies still run exposed boxes.
night_shift
Patch today. Hunt affiliates tomorrow.
Inspired by public posts on X — paraphrased, not attributed.