The Gunra ransomware gang is leveraging vulnerabilities in Fortinet firewalls and VPN appliances, combined with leaked Conti code, to successfully target critical infrastructure. Specifically, the group is exploiting known flaws to bypass multi-factor authentication, gaining unauthorized access to sensitive systems. This approach has proven effective, allowing the gang to compromise high-value targets with relative ease. The use of outdated vulnerabilities, such as those found in older Fortinet devices, underscores the importance of regular patching and maintenance. The gang's ability to bypass MFA1 highlights the need for robust security measures beyond simple authentication protocols. This development matters to security practitioners because it underscores the importance of proactive operational resilience planning, particularly in sectors with critical infrastructure, to mitigate the risk of ransomware attacks.
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
⚠️ Critical Alert
Why This Matters
Ransomware targeting Fortinet highlights sector-specific risk — operational resilience planning is the real takeaway.
References
- Dark Reading. (2026, August 11). Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA. Dark Reading. https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa
Original Source
Dark Reading
Read original →