Authorities flagged a Fortinet bypass that opened the floodgates for a major ransomware campaign.
A security notice from the likes of the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned known Fortinet VPN vulnerabilities are currently being leveraged by the Gunra ransomware group to evade multifactor authentication, extract confidential corporate data, and lock down affected systems.
The attacks hinge around two Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, which exploit scheduled tasks on compromised FortiOS firewall devices to forge a new, malicious persistent user with super user privileges and a hard-coded password.
Organizations were recommended to prioritize patches for exposed Fortinet firewalls, VPN, and remote-access infrastructure, as well as restrict internet-facing management access, enforce least privilege and multifactor authentication, and segment networks. In the event of a suspected compromise, CISA advised to isolate affected systems and preserve forensic evidence. Enterprises were also recommended to disable attacker-controlled accounts and secure credentials before restoration.
Government and critical infrastructure is under threat from the attack wave, which expanded earlier this year when the Gunra group expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program.
The group has not yet been affiliated with any particular nation, although its tooling and infrastructure has been associated with North Korea-linked activity.
