Gunra Ransomware Gang Bypasses MFA by Exploiting Old Fortinet Vulnerabilities
A ransomware-as-a-service operation known as Gunra is gaining traction by targeting critical infrastructure organisations through known vulnerabilities in Fortinet firewalls and VPN appliances. The group has built its malware using leaked source code from the notorious Conti ransomware gang, allowing it to launch effective attacks without having to develop its tools from scratch.
What makes this campaign particularly concerning is Gunra's ability to bypass multi-factor authentication (MFA) by exploiting older, unpatched flaws in Fortinet devices. MFA is widely regarded as a strong defence against unauthorised access, but this case shows that outdated firmware and unpatched systems can undermine even well-established security controls. Attackers are increasingly focused on finding the weakest link in an organisation's defences rather than attempting to break through modern protections directly.
For Australian small businesses using Fortinet or similar network security appliances, this serves as a reminder that perimeter devices such as firewalls and VPNs require the same diligent patch management as any other critical system. Even organisations with MFA in place remain vulnerable if the underlying infrastructure has known, unpatched security gaps.