CISA, FBI and four other agencies warn that Gunra, a Conti derived ransomware as a service operation, is exploiting two known Fortinet flaws against healthcare, finance and government targets.
CISA, the FBI, the Defense Cyber Crime Center, NSA, the U.S. Secret Service, and the Republic of Korea's National Policy Agency warned on Aug. 10, 2026 that the Gunra ransomware-as-a-service operation is hitting healthcare, financial services, government facilities, and other critical-infrastructure operators worldwide.
The joint advisory AA26-222a names the initial-access path: exploitation of two known Fortinet authentication flaws in internet-facing FortiOS and FortiProxy devices, CVE-2024-55591 and CVE-2025-24472, plus credential and SSH weaknesses on VPN gateways. Both CVEs are months old with published patches, a patch-now story rather than a zero-day.
Gunra is built on the Conti source code leaked in February 2022, emerged in April 2025, and stood up a formal affiliate program on dark-web forums in January 2026 as "Golden Community." It runs double-extortion, exfiltrates data before encrypting, and negotiates through a Tor-based portal with a 5–7 day payment window. The FBI has observed Gunra operators emailing victim management directly to push payment.
CISA Acting Executive Assistant Director for Cybersecurity Chris Butera urged operators to patch internet-facing systems now, segment networks, and align backups to the agency's Cross-Sector Cybersecurity Performance Goals. South Korean firm AhnLab has linked Gunra operations to North Korea's Lazarus Group, a state-nexus overlay the US advisory does not formally attribute. The Register first reported the warning. The advisory does not include victim counts or exploitation volume.