this ransomware gang doesn't crack your MFA. it just tells the server to say yes

Six government agencies just confirmed a ransomware crew is rewriting authentication files on Fortinet VPN portals so a single fake one-time code…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

Gunra gets initial access through two patched Fortinet flaws: CVE-2024-55591 (CVSS 9.6, FortiOS/FortiProxy auth bypass) and CVE-2025-24472 (CVSS 8.1, CSF proxy auth bypass).

What you need to know

In at least one documented case, they modified authentication files on a corporate VDI portal so a Gunra-chosen OTP value always authenticates — MFA becomes decorative.

What you need to know

CISA, the FBI, and South Korea's National Police Agency issued the joint advisory on August 11, 2026.

What you need to know

Gunra has hit at least 51 organizations since emerging in April 2025, mostly healthcare, financial services and government, concentrated in Australia, East Asia and Europe.

What you need to know

Fix CVE-2024-55591 by upgrading to FortiOS 7.0.17+ or FortiProxy 7.0.20+/7.2.13+; fix CVE-2025-24472 per Fortinet advisory FG-IR-24-535.

Bottom line

Patch both Fortinet CVEs today if you haven't, then go check your VDI portal's auth files by hand — this is one of those advisories where 'we're patched' and 'we're safe' are not the same sentence.

Aliteq

Read the full story

this ransomware gang doesn't crack your MFA. it just tells the server to say yes

Read the full story on Aliteq