Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gunra ransomware mitigation advisory (CISA/FBI/partners)

Advisory/Mitigation
First reported
Last updated
Happening score
H score 26
4 unique sources, 4 articles

Summary

Hide ▲

Gunra ransomware is the focus of a joint advisory from CISA, FBI, DC3, NSA, USSS, and KNPA warning critical infrastructure organizations worldwide. The advisory says the RaaS operation first emerging in April 2025 and tied to leaked Conti source code gains initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in Fortinet FortiOS/FortiProxy devices. It also says Gunra actors use stolen credentials, MFA bypass, OpenSSH, and Microsoft 365 exfiltration to move laterally, steal data, and pressure victims with double extortion. The advisory recommends patching exposed systems, limiting lateral movement, and maintaining immutable backups while it provides detection guidance and IOCs.

Related Happenings

Gunra launches RaaS affiliate program and recruits initial access brokers

Threat Actor Meta
H score32 First: 11.08.2026 12:47 Last: 11.08.2026 12:47 Sources 1

How related: In early 2026, the group developed a structured RaaS affiliate program advertised on dark web forums.

About this happening: Gunra expanded its criminal operating model in January 2026 by launching a ransomware-as-a-service (RaaS) platform and recruiting initial access brokers. The group...

Gunra ransomware CVE exploitation and double-extortion activity

Malware Activity
H score26 First: 10.08.2026 15:00 Last: 10.08.2026 15:00 Sources 1

How related: Gunra ransomware actors are exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations, a joint advisory issued by US and Republic of Korea authorities has warned.

About this happening: Gunra ransomware is an RaaS operation targeting government and critical national infrastructure organizations, with a joint US/Republic of Korea advisory warni...

Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign

Campaign
H score55 First: 24.07.2026 10:36 Last: 24.07.2026 10:36 Sources 1

About this happening: The Clop/Cl0p campaign against PTC Windchill and FlexPLM now includes a bespoke JSP web shell tied to CVE-2026-12569. ReliaQuest said the implant is built to dec...

Latest development: 18.08.2026 20:29

A custom Java web shell designed for PTC Windchill and FlexPLM servers was likely deployed in recent data theft attacks exploiting CVE-2026-12569, and it includes built-in features to decrypt credentials, enumerate file repositories, and steal files. The implant uses X-windchill-req control messages, imports Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, and appears to be an application-specific evolution of Clop's mass-exploitation playbook.

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...

CISA-led joint advisory on Russian router targeting

Public Sector Action
H score32 First: 14.07.2026 15:00 Last: 14.07.2026 15:00 Sources 1

About this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...

Timeline

  1. 10.08.2026 15:00 5 articles · 13d ago

    CISA, FBI, DC3, NSA, USSS, and KNPA warn on Gunra ransomware

    Initial Disclosure

    CISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory, #StopRansomware: Gunra Ransomware, warning that Gunra ransomware affiliates target critical infrastructure sectors worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion through data exfiltration and data encryption, while providing tailored detection guidance, IOCs, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).

    Show sources