tech π¨ Gunra ransomware bypasses MFA via Fortinet VPN flaws
A joint advisory exposed the Gunra ransomware group exploiting Fortinet VPN vulnerabilities to steal enterprise data. This group, which matured into a ransomware-as-a-service model, was observed by the FBI and others. Attacks leverage flaws like CVE-2024-55591 and CVE-2025-24472, with one case neutralizing MFA by tampering with auth files. Gunra exfiltrates massive datasets to Mega before deploying ChaCha20 encryption. Organizations must patch VPNs and maintain immutable backups to counter these threats.