Gunra Ransomware Targets Fortinet and Schneider Electric Vulnerabilities to Infiltrate Networks
Cybersecurity agencies from South Korea and the United States have issued a joint warning about Gunra ransomware attacks affecting critical infrastructure and organizations globally. The threat actors behind Gunra have been targeting sectors including healthcare and public health, financial services, government services, and professional and nonprofit organizations.
According to the advisory, Gunra represents the latest entry in an ongoing trend of ransomware groups exploiting known security vulnerabilities in widely used network and industrial equipment. In this case, attackers are leveraging flaws in Fortinet devices and Schneider Electric products to gain initial access to victim networks before deploying ransomware. Fortinet firewalls and VPNs are commonly used by businesses of all sizes to secure network perimeters, while Schneider Electric products are widely deployed in industrial and operational technology environments, making unpatched systems an attractive target.
This pattern underscores a persistent challenge for organizations: known, publicly disclosed vulnerabilities remain one of the most common entry points for ransomware gangs, often because patches are available but not applied quickly enough. Businesses relying on Fortinet or Schneider Electric equipment should review vendor security advisories and confirm their systems are running the latest patched versions.