Joint advisory details double-extortion operations, Fortinet authentication flaws, widespread targeting of healthcare, finance, manufacturing, transport, utilities, academia worldwide
US cybersecurity and intelligence officials are sounding the alarm on a new ransomware strain that has rapidly become a global threat. In a joint advisory published on 11 Aug 2026 (US time), multiple federal agencies warned that the Gunra ransomware family is being used in widespread attacks on government networks, hospitals, financial institutions, and other critical infrastructure organizations across several continents, according to The Hill.
The alert comes from a coalition that includes the Cybersecurity and Infrastructure Security Agency), the FBI, the National Security Agency, the Department of Defense Cyber Crime Center, the US Secret Service, and South Korea’s National Police Agency, classifying Gunra as a Ransomware-as-a-Service platform (RaaS.
Investigators say the variant was first identified in 2025. By 2026, it had matured into a full-fledged RaaS ecosystem, with multiple criminal groups deploying it in live operations using double-extortion.
CISA’s analysis highlights that Gunra actors have capitalized on two specific vulnerabilities to breach networks: CVE-2024-55591 and CVE-2025-24472. Both flaws are described as authentication bypass issues affecting Fortinet’s products, and successful exploitation can grant an attacker remote super-admin rights over targeted devices.
The campaign is not limited to one region or vertical. Gunra operators have struck organizations throughout the Americas, Europe, the Middle East, Africa, and the Asia Pacific region. Victim sectors span healthcare providers, financial services firms, critical manufacturing plants, transportation operators, government entities, utilities, and academic institutions. Once inside a victim’s environment, the actors work to conceal their activities by deleting access logs and clearing command histories. Only after they have reduced their forensic footprint do they focus on harvesting business-critical records such as documents, databases, and stores of personally identifiable information, according to the joint advisory.
This guidance forms part of the US government’s broader #StopRansomware initiative. By spotlighting Gunra’s techniques and preferred attack paths, the agencies aim to give organizations worldwide a clearer picture of the threat, and practical steps to strengthen their defenses.
