US cyber agencies have issued a warning to critical infrastructure operators to patch their internet-facing systems after discovering that Gunra ransomware affiliates are exploiting known vulnerabilities to gain access to networks. This warning comes as the attackers have been found to exploit Fortinet flaws, leading to administrative access and the execution of a double-extortion strategy.
Key Insights
Gunra ransomware is specifically exploiting known bugs to target critical infrastructure, leveraging Fortinet flaws to achieve administrative access. Once inside, Gunra affiliates follow a double-extortion playbook, which involves stealing sensitive data and then demanding payment in exchange for a decryptor to restore access to the compromised data.










