Threat Intelligence

Gunra Ransomware Targets Fortinet and Schneider Electric Vulnerabilities to Infiltrate Networks

The Hacker News · 11 Aug 2026
Key Takeaway Regularly check for and apply security patches on network devices like firewalls and VPNs, since unpatched known vulnerabilities remain a top entry point for ransomware attacks.

Cybersecurity agencies from South Korea and the United States have issued a joint warning about Gunra ransomware attacks affecting critical infrastructure and organizations globally. The threat actors behind Gunra have been targeting sectors including healthcare and public health, financial services, government services, and professional and nonprofit organizations.

According to the advisory, Gunra represents the latest entry in an ongoing trend of ransomware groups exploiting known security vulnerabilities in widely used network and industrial equipment. In this case, attackers are leveraging flaws in Fortinet devices and Schneider Electric products to gain initial access to victim networks before deploying ransomware. Fortinet firewalls and VPNs are commonly used by businesses of all sizes to secure network perimeters, while Schneider Electric products are widely deployed in industrial and operational technology environments, making unpatched systems an attractive target.

This pattern underscores a persistent challenge for organizations: known, publicly disclosed vulnerabilities remain one of the most common entry points for ransomware gangs, often because patches are available but not applied quickly enough. Businesses relying on Fortinet or Schneider Electric equipment should review vendor security advisories and confirm their systems are running the latest patched versions.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.