[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frPSz7H5YczyoFXCNddqDOgLkWtcCRJscDTW47ecHnjU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"cf68f552-68cf-41fe-a372-2cd78f0e31a6","gunra-ransomware-exploits-unpatched-fortinet-devices-and-bypasses-mfa","c0c979ec-54f7-4ed8-85d1-af2078e876c3","Gunra Ransomware Exploits Unpatched Fortinet Devices and Bypasses MFA","The Gunra ransomware group is actively exploiting known, older vulnerabilities in Fortinet firewall and VPN appliances — meaning affected organizations had windows of opportunity to patch but did not act in time. Compounding the risk, the group leverages leaked Conti ransomware code to circumvent MFA protections, demonstrating that MFA alone is insufficient when underlying systems remain unpatched and misconfigured. This attack highlights a dangerous assumption: that implementing a single control like MFA constitutes adequate defense. Internet-facing network appliances are high-value targets, and delayed patching of these devices can expose an organization's entire network perimeter. The combination of unpatched vulnerabilities and MFA bypass capability significantly lowers the barrier for ransomware actors to compromise critical infrastructure.","**Immediate actions:**\n- Apply all available Fortinet security patches immediately, prioritizing internet-facing firewall and VPN appliances.\n- Audit MFA configurations across all remote access points to identify and remediate bypass-prone implementations (e.g., legacy protocols, MFA fatigue vulnerabilities).\n- Isolate unpatched Fortinet appliances from critical network segments until remediation is complete.\n\n**Long-term improvements:**\n- Establish a formal, risk-prioritized patch management program with defined SLAs for critical CVEs on perimeter devices (e.g., patch within 24–72 hours of disclosure).\n- Maintain a continuously updated inventory of all internet-facing appliances and their firmware\u002Fsoftware versions.\n- Adopt a Zero Trust architecture so that no single compromised perimeter device grants broad internal network access.\n\n**Detection measures:**\n- Deploy continuous vulnerability scanning specifically targeting perimeter and network appliances using tools like Tenable or Qualys.\n- Implement behavioral monitoring and SIEM alerting for anomalous authentication patterns, including MFA bypass indicators and lateral movement from VPN endpoints.\n- Subscribe to vendor security advisories (e.g., Fortinet PSIRT) and threat intelligence feeds to receive real-time notification of exploited vulnerabilities.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 6: Access Control Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 AC-17: Remote Access","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","NIST CSF PR.AC-3: Remote Access Managed","ITIL Change Management: Emergency Change Procedures","MITRE ATT&CK T1190: Exploit Public-Facing Application","MITRE ATT&CK T1556: Modify Authentication Process","published","2026-08-11T22:21:09.18044+00:00","2026-08-11T22:21:08.891+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fgunra-ransomware-gang-fortinet-flaws-bypasses-mfa","gunra-ransomware-gang-exploits-fortinet-flaws-bypasses-mfa-555682","Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]