Exploited in the wild FortiOS Gunra ransomware FortiProxy Fortinet
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
CVE Tools coverage
The FBI and South Korean authorities have issued a joint alert identifying Gunra as an active ransomware-as-a-service operation targeting critical infrastructure and government entities worldwide. The group is actively exploiting CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities in FortiOS and FortiProxy, to gain initial access to networks. In one observed attack vector, Gunra affiliates manipulated VDI portals to capture employee session data, allowing them to completely circumvent multi-factor authentication protections. Agencies advise immediate patching of affected appliances alongside the implementation of immutable offline backups and strict network segmentation.