Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Summary
The Gunra ransomware gang is reportedly exploiting unpatched vulnerabilities in Fortinet firewalls and VPN appliances, including older flaws, to gain access to critical infrastructure. This operation is leveraging leaked Conti ransomware code and has been observed successfully bypassing multi-factor authentication (MFA).
IFF Assessment
This article details successful exploitation of vulnerabilities, allowing ransomware to bypass security measures and target critical infrastructure, which is detrimental to defenders.
Defender Context
Defenders need to ensure that Fortinet devices and other edge infrastructure are patched promptly, especially for known vulnerabilities that ransomware groups are actively exploiting. The ability of attackers to bypass MFA highlights the need for robust authentication mechanisms and layered security defenses.