CVE Tools
Back to feed
Exploited in the wild FortiOS ransomware FortiProxy Fortinet zero-day

US and South Korea warn of Gunra ransomware targeting govt agencies

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

The U.S. Department of Homeland Security and South Korea’s National Policy Agency have issued a joint advisory warning that the Gunra ransomware group is actively targeting government agencies and critical infrastructure. The threat actor utilizes malware derived from the leaked Conti source code to compromise systems across various sectors, including healthcare and finance.

Investigators report that Gunra specifically exploits authentication vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet products, such as FortiOS and FortiProxy, alongside SSH misconfigurations to establish footholds. Defenders are urged to apply patches immediately, segment networks to limit lateral movement, and maintain offline backups to mitigate these expanding threats.