Fortinet, Schneider flaws weaponized in Gunra ransomware

Critical infrastructure operators are being urged to patch exposed Fortinet and Schneider Electric systems after a new Gunra ransomware campaign was observed abusing known flaws in both vendors’ products to gain initial access, steal data and encrypt networks across multiple sectors worldwide.[1][3] Cybersecurity and intelligence agencies in South Korea and the United States have issued a joint warning that Gunra is actively targeting healthcare, financial services, government entities and nonprofit organizations in a double‑extortion operation.[1][3]

Researchers report that Gunra operators are exploiting a vulnerability in Schneider Electric PowerLogic P5 power meters, tracked as CVE‑2024‑5559, to compromise internet‑facing devices often deployed in energy management and industrial environments.[1][3][8] Once inside, the attackers pivot from these operational technology gateways into adjacent IT networks, using the foothold to enumerate assets, steal sensitive files and prepare for ransomware deployment.[1][3] Organizations relying on PowerLogic P5 equipment are being advised to inventory any devices reachable from the public internet and verify that vendor security updates have been applied.[3][10][12]

On the network security side, the same campaign has been observed leveraging a flaw in Fortinet FortiOS and FortiProxy appliances identified as CVE‑2025‑24472, allowing the attackers to break into perimeter firewalls and VPN concentrators before pushing Gunra payloads further into corporate environments.[1][3][8] Compromised Fortinet devices are used to harvest credentials, deploy additional malware and disable security tools, clearing the way for large‑scale encryption of servers, databases and network‑attached storage systems.[1][8] Fortinet customers are being urged to review the company’s security advisories on its PSIRT portal[11] and apply all available fixes or mitigations for affected FortiOS and FortiProxy versions.[11][13][14]

The Gunra activity comes amid broader concern over Fortinet’s attack surface, highlighted by a separate authentication‑bypass vulnerability in FortiCloud single sign‑on, CVE‑2026‑24858, which affects FortiAnalyzer, FortiManager, FortiOS, FortiProxy, FortiWeb and other products.[5][9] The flaw, categorized as an “Authentication Bypass Using an Alternate Path or Channel,” may allow an attacker with a FortiCloud account and a registered device to log into other devices tied to different accounts when FortiCloud SSO is enabled.[5] The issue has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, signaling confirmed use in real‑world attacks and elevating patching urgency for impacted systems.

Once Gunra actors establish access through vulnerable Schneider Electric or Fortinet devices, they reportedly follow a playbook familiar from other modern ransomware crews: exfiltrating sensitive data before encrypting it, then threatening both operational downtime and public leaks if victims refuse to pay.[1][3][8] The campaign has been linked to attacks that disrupted business operations by locking up databases, hypervisors and backup systems, while the stolen information is used as leverage on dedicated extortion sites and via direct pressure on corporate leadership.[1][3] At this stage, public reporting has not attributed Gunra to a specific threat group, underscoring that multiple financially motivated actors may seek to copy these techniques as long as the underlying flaws remain unpatched.[1][3]

Defenders are being urged to prioritize patching Schneider Electric PowerLogic P5 devices affected by CVE‑2024‑5559 and Fortinet FortiOS/FortiProxy systems vulnerable to CVE‑2025‑24472, alongside the separate FortiCloud SSO issue CVE‑2026‑24858.[1][3][5][9] Security teams should reduce direct internet exposure of management interfaces, enforce multi‑factor authentication on remote access, and monitor for unusual FortiCloud logins or configuration changes on Fortinet equipment. Regular, offline‑protected backups and tested incident‑response plans remain critical to limiting downtime and recovery costs in the event that Gunra or similar ransomware successfully breach critical infrastructure networks.[1][3][15]

References

  1. Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws …
  2. Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws …
  3. CVE-2026-24858 Detail – NVD
  4. The Hacker News’ Post
  5. Fortinet’s latest zero-day vulnerability carries frustrating …
  6. Schneider-electric Vulnerabilities – Feedly
  7. PSIRT Advisories
  8. Schneider-electric CVEs and Security Vulnerabilities – OpenCVE
  9. Latest Fortinet Vulnerabilities
  10. Fortinet CVEs and Security Vulnerabilities – OpenCVE
  11. Multiple Vulnerabilities in Fortinet Products Could Allow …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply