← Back to Feed

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

August 11, 2026 · Dark Reading · Severity: CRITICAL

The Gunra ransomware-as-a-service operation is successfully targeting critical infrastructure by exploiting old Fortinet flaws and bypassing multi-factor authentication. The gang uses leaked Conti code and exploits vulnerabilities in firewalls and VPN appliances. This approach has proven effective against critical infrastructure targets.

Key Takeaways

  • Gunra ransomware gang exploits old Fortinet flaws and bypasses MFA.
  • The operation uses leaked Conti code to target critical infrastructure.
  • Success comes from exploiting flaws in firewalls and VPN appliances.
☕ Buy a Coffee