Cyber Resilience
← All news
Corroborated

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Our takeGunra ransomware is exploiting known Fortinet flaws (including MFA bypasses) and Schneider Electric bugs to hit critical infrastructure worldwide. Patch the affected systems now if you run them yourself; smaller teams may need to make sure their MSP patch the Fortinet flaws.
Sources (2)
What this means for you — Security leader:Patch Fortinet firewalls and VPNs (especially CVE-2024-55591 and related) and review MFA configurations on edge appliances. Gunra is actively exploiting these to deploy ransomware against critical infrastructure.
What this means for you — Lean IT orgs:If you run Fortinet firewalls or Schneider Electric gear yourself, update them immediately. Most lean teams should also ask their MSP or internet provider whether their edge devices are current.
What this means for you — MSP:Audit all managed Fortinet firewalls, VPNs, and Schneider Electric devices for the listed vulnerabilities and ensure MFA is enforced on management interfaces. Gunra is using these exact flaws plus Conti-derived ransomware against critical-infrastructure clients.
What this means for you — Researcher:Gunra ransomware (Conti code leak derivative) is exploiting known Fortinet flaws (including MFA bypass) and Schneider Electric vulnerabilities to target healthcare, finance, government, and critical infrastructure globally.