Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
CISA, FBI, and South Korean agencies warn Gunra ransomware, with 51 victims since April 2025, exploits Fortinet flaws for double-extortion attacks on critical infrastructure.
CISA, the FBI, and South Korean agencies warned of Gunra ransomware attacks targeting healthcare, financial services, government, and professional services worldwide. The Conti-derived operation exploits internet-facing Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 for initial access, then deploys double extortion with Salsa20/ChaCha20 encryption and publishes non-payers on a leak site within five to seven days. Ransomware.Live lists 51 victims since April 2025, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group uses Impacket tools for SMB lateral movement and NTDS credential dumping, tampers with VDI authentication to accept a designated OTP value to bypass MFA, and launched a RaaS affiliate program in January 2026 under the new alias Golden Community.
September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.
Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.
August 2026 CVE Landscape
Insikt Group catalogs 73 high-impact August 2026 CVEs (43 Very Critical), including PaperCut, Zimbra, and Metabase flaws actively exploited or weaponized.
Recorded Future's Insikt Group identified 73 high-impact vulnerabilities in August 2026, 43 rated Very Critical, spanning 45 vendors with Microsoft accounting for roughly 11%. 31 vulnerabilities surfaced via CISA's KEV catalog, with others validated via open sources, vendor telemetry, and honeypot data. New Nuclei detection templates were released for CVE-2025-62593 (Ray), CVE-2026-72898 (Metabase), and CVE-2026-9198 (IBM Langflow). The report also highlights two AI-assisted operations: UAT-10147 exploited Zimbra, AjaxPro, Nacos, and Telerik servers before using DeepAudit and PentestGPT post-compromise, while a separate Chinese-speaking actor weaponized Hermes Agent and DeepSeek in a failed attempt.