As cited
Copy frozen at (site build).
ransomware
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, the FBI, and international partners issued a joint advisory warning of Gunra ransomware-as-a-service (RaaS) attacks targeting government, critical infrastructure, and healthcare organizations across multiple regions. The group, which transitioned to RaaS in 2026, recruits affiliates with an 80% ransom share, exploits known vulnerabilities in firewalls and virtual private networks (VPNs) such as CVE-2024-55591 and CVE-2025-24472, and conducts double extortion by stealing data before encryption. The advisory recommends prioritizing patches for VPN and remote desktop protocol exposed infrastructure, network segmentation, and immutable backups in separate locations.
Why it matters: Healthcare organizations and other critical infrastructure operators face immediate threats from a rapidly expanding RaaS group; teams should patch known FortiOS/FortiProxy and VPN vulnerabilities and validate backup isolation to prevent both encryption and data exfiltration losses.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Healthcare Orgs Warned About Gunra Ransomware Attacks
CISA, the FBI, and international partners issued a joint advisory warning of Gunra ransomware-as-a-service (RaaS) attacks targeting government, critical infrastructure, and healthcare organizations across multiple regions. The group, which transitioned to RaaS in 2026, recruits affiliates with an 80% ransom share, exploits known vulnerabilities in firewalls and virtual private networks (VPNs) such as CVE-2024-55591 and CVE-2025-24472, and conducts double extortion by stealing data before encryption. The advisory recommends prioritizing patches for VPN and remote desktop protocol exposed infrastructure, network segmentation, and immutable backups in separate locations.
Why it matters: Healthcare organizations and other critical infrastructure operators face immediate threats from a rapidly expanding RaaS group; teams should patch known FortiOS/FortiProxy and VPN vulnerabilities and validate backup isolation to prevent both encryption and data exfiltration losses.
- Source published
- First seen by Cybersecurity Tracker