Cybersecurity authorities from the United States and South Korea have warned of active Gunra ransomware campaigns exploiting vulnerabilities in equipment from Fortinet and Schneider Electric.

According to a report from The Hacker News, the threat actors are targeting flaws in widely deployed networking and industrial control systems. These vulnerabilities provide initial access, often bypassing standard perimeter defenses. Once inside networks, Gunra operators deploy a double-extortion model—exfiltrating data before encryption—to pressure victims into payment.

The advisory identifies healthcare, financial services, government facilities, and professional or nonprofit organizations as primary targets. This cross-border alert underscores the global nature of the threat and the value of synchronized intelligence sharing to disrupt attack timelines.

Security analysts highlight that Gunra's approach represents a deliberate shift in ransomware tactics: weaponizing vulnerabilities in edge networking and operational technology (OT) hardware. With both vendors maintaining massive global footprints across enterprise IT and industrial environments, the attack surface is expansive. This makes proactive vulnerability management a foundational requirement for any organization managing hybrid infrastructure.

Immediate action is required. The advisory prioritizes three core defensive pillars: deploy vendor-supplied patches for the relevant vulnerabilities, enforce strict network segmentation to isolate critical OT and edge systems, and mandate multi-factor authentication across all remote access points. Organizations should also hunt for compromise using the published indicators of compromise (IOCs).

For IT and open-source security communities, this campaign emphasizes the growing convergence of IT and industrial control system protection. Transparency in vulnerability disclosure and rapid patching are crucial, and open-source tools will play an increasingly vital role in monitoring IOCs and implementing controls.

While the advisory does not target specific regions, the widespread use of affected hardware means professionals worldwide must treat this guidance as high-priority. As ransomware groups refine their focus on foundational infrastructure, coordinated international alerts and disciplined patch hygiene remain essential defenses against disruption.


美國及韓國的網絡安全機構警告,活躍的Gunra勒索軟件攻擊正利用Fortinet及Schneider Electric設備中的漏洞。

據The Hacker News報導,威脅行為者正針對廣泛部署的網絡設備及工業控制系統的缺陷發動攻擊。這些漏洞能提供初始入侵途徑,且往往能繞過標準周邊防禦措施。一旦進入網絡,Gunra運營者會採用「雙重勒索」模式——先竊取數據再進行加密——以迫使受害者支付贖金。

該警告指出,醫療保健、金融服務、政府機構以及專業或非營利組織是主要攻擊目標。這項跨境警報突顯了威脅的全球性質,以及同步情報共享在阻斷攻擊時間線方面的價值。

安全分析師指出,Gunra的策略代表了勒索軟件戰術的刻意轉變:將漏洞武器化針對邊緣網絡及營運技術(OT)硬件。由於這兩家供應商在企業IT及工業環境中均佔有龐大全球市場,攻擊面極為廣泛。這使得主動的漏洞管理成為任何管理混合基礎設施組織的基礎要求。

必須立即採取行動。該警告確定了三大核心防禦支柱:為相關漏洞部署供應商提供的補丁、實施嚴格網絡分隔以隔離關鍵OT及邊緣系統、以及在所有遠端訪問點強制執行多重身份驗證。組織亦應根據公佈的入侵指標(IOC)排查是否已遭入侵。

對於IT及開源安全社群而言,此次攻擊行動凸顯了IT與工業控制系統防護日益融合的趨勢。漏洞披露的透明度和快速打補丁至關重要,開源工具在監控IOC和實施控制方面將扮演越來越重要的角色。

雖然該警告並未針對特定地區,但受影響硬件的廣泛使用意味著全球專業人士都必須將此指引視為優先事項。隨著勒索軟件組織加強對基礎設施的針對性攻擊,國際協調警報與嚴謹的補丁管理仍是抵禦網絡破壞的基本防線。

新聞來源 / Original News Source