US warns that Gunra ransomware is exploiting Fortinet flaws to target critical systems
American cyber agencies have alerted operators of essential services to patch known Fortinet vulnerabilities after Gunra ransomware affiliates used them to breach networks and launch double-extortion attacks.
US cyber-defense bodies, including CISA, the FBI, NSA and the Secret Service, together with South Korean counterparts, have warned that the Gunra ransomware gang is exploiting two known Fortinet authentication-bypass flaws - CVE-2024-55591 and CVE-2025-24472 - to infiltrate internet-facing firewalls and proxies. Operating as a ransomware-as-a-service, Gunra affiliates have targeted a range of critical-infrastructure sectors such as healthcare, finance, government and nonprofit organizations across multiple continents.
Their attack follows the classic double-extortion model: data is exfiltrated, systems are encrypted, and victims are pressured to pay for a decryption key and a promise not to release the stolen information, with a typical deadline of five to seven days. Trend Micro, which first identified the group in April 2025, notes a Linux variant capable of running up to 100 encryption threads and performing partial file encryption. The advisory urges organizations to apply patches, enforce multi-factor authentication on VPN and RDP access, segment networks and maintain offline, immutable backups to mitigate the threat.
Why it matters
Unpatched Fortinet devices could let ransomware cripple essential services worldwide.
In this story