CISA and FBI Warn Hospitals of Gunra Ransomware Attacks Exploiting Fortinet VPN Flaws
CISA, the FBI, and international partners issued a joint advisory warning that the Gunra ransomware group is actively exploiting known Fortinet VPN vulnerabilities to breach hospitals and critical infrastructure. Gunra steals data before encrypting systems and threatens to leak i
Federal cyber authorities are warning healthcare systems and critical infrastructure operators about the Gunra ransomware group, which is actively exploiting exposed VPN devices. CISA, the FBI, and international partners detail how Gunra exploits two known Fortinet FortiOS and FortiProxy vulnerabilities, plus SSH access control flaws in VPN gateways, to breach networks, steal data, and then encrypt files, giving victims 5 to 10 days before stolen data is published on a dark web leak site. More than 30 victims are already listed. The group, built from leaked Conti ransomware source code, now operates as a ransomware-as-a-service model offering affiliates an 80 percent cut of ransom payments.