Gunra Ransomware Exploiting Fortinet and Schneider Electric Vulnerabilities to Target Critical Infrastructure Globally
Cybersecurity and intelligence agencies from South Korea and the U.S. have issued a joint warning regarding Gunra ransomware attacks. The ransomware is actively exploiting security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to gain initial access to critical infrastructure sectors worldwide, including healthcare, financial services, and government. The attacks employ a double extortion model involving data exfiltration and encryption.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai