← Back to Feed
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
August 11, 2026 · Dark Reading · Severity: CRITICAL
The Gunra ransomware-as-a-service operation is successfully targeting critical infrastructure by exploiting old Fortinet flaws and bypassing multi-factor authentication. The gang uses leaked Conti code and exploits vulnerabilities in firewalls and VPN appliances. This approach has proven effective against critical infrastructure targets.
Key Takeaways
- Gunra ransomware gang exploits old Fortinet flaws and bypasses MFA.
- The operation uses leaked Conti code to target critical infrastructure.
- Success comes from exploiting flaws in firewalls and VPN appliances.