Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Summary

The Gunra ransomware gang is reportedly exploiting unpatched vulnerabilities in Fortinet firewalls and VPN appliances, including older flaws, to gain access to critical infrastructure. This operation is leveraging leaked Conti ransomware code and has been observed successfully bypassing multi-factor authentication (MFA).

IFF Assessment

FOE

This article details successful exploitation of vulnerabilities, allowing ransomware to bypass security measures and target critical infrastructure, which is detrimental to defenders.

Defender Context

Defenders need to ensure that Fortinet devices and other edge infrastructure are patched promptly, especially for known vulnerabilities that ransomware groups are actively exploiting. The ability of attackers to bypass MFA highlights the need for robust authentication mechanisms and layered security defenses.

Read Full Story →