Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Joint warnings from U.S. and South Korean cybersecurity agencies reveal that the Gunra ransomware operation is actively compromising critical infrastructure sectors, including healthcare, finance, and government entities. Attackers are gaining initial access by exploiting specific vulnerabilities in internet-facing devices, specifically Fortinet FortiOS and FortiProxy (CVE-2025-24472) and Schneider Electric PowerLogic P5 (CVE-2024-5559).
Once inside the network, the threat actor employs a double-extortion strategy involving data exfiltration and encryption, utilizing advanced lateral movement tools and credential harvesting techniques. CISA advises organizations to immediately apply patches for these known exploited vulnerabilities, enforce network segmentation, and maintain immutable backups to mitigate potential impact.