U.S. and South Korean Agencies Warn of Global Gunra Ransomware Attacks on Critical Infrastructure
A joint advisory from U.S. cybersecurity authorities and South Korea’s National Police Agency warns of widespread Gunra ransomware attacks targeting sectors such as healthcare, finance, government, and manufacturing. First appearing in April 2025 as a double-extortion operation derived from leaked Conti source code, Gunra exploits known vulnerabilities in Fortinet FortiOS/FortiProxy appliances (CVE-2024-55591, CVE-2025-24472) and Schneider Electric devices, as well as credential-exposure flaws in VPN gateways, to gain remote access. The group has claimed 51 victims worldwide—mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong—and launched a formal ransomware-as-a-service program in January 2026, recruiting initial access brokers. Gunra initially targeted Windows systems but added a Linux variant in mid-2025, and affiliates are provided with a management panel, configurable builder, cross-platform payloads, and documentation. The attacks also bypass multi-factor authentication via Fortinet flaws, and the ransomware can encrypt files as large as 9TB rapidly using Salsa20 or ChaCha20 stream ciphers.

The Ghost in the Machine

You need to understand that the Gunra ransomware is not simply a group of criminals with clever code. It is a managed asset, a black-ops tool that has been deliberately released into the wild to perform a very specific function: to create the crisis that justifies the control. Look at the timeline. The code is derived from the leaked Conti source code. Ask yourself this: who benefits from leaking a proven, state-grade weapon to the criminal underground? The answer is always the same institutional architects who need a visible, digital "terror" to ram through a global surveillance and data control regime. They don't just let this technology walk out the door. It is cultivated, seeded, and then amplified by the very advisory infrastructure that claims to be fighting it.

The Footholds Were Built for Them

Notice the technical details that the mainstream outlets like The Hacker News are forced to report, even if they don't connect the dots. The vulnerabilities they are exploiting—Fortinet firewalls, VPN gateways, Schneider Electric industrial controllers—these are not random holes in the digital fabric. These are deliberately preserved back doors that have been left open across critical infrastructure for years. CVE-2024-55591 and CVE-2024-5559? These are not new discoveries. They were known, catalogued, and left unpatched because the Architecture of Consent requires a certain level of vulnerability to justify the next quantum leap in security theater. The MFA bypass? That’s the tell. If they can bypass your multi-factor authentication, then “authentication” itself becomes a meaningless concept, and the only logical solution becomes a centralized, biometric, government-verified digital identity for everything. They are shepherding you toward the cage.

The Breadcrumb Trail to Nowhere

Look at the victimology. They tell you 51 victims total, but almost none in the United States. Why? Because this operation has a geopolitical phase line. South Korea is the proving ground. Brazil, Spain, Thailand—these are the test beds for the Linux expansion and the affiliate program. They are perfecting the knife on the periphery before they drive it into the heart of the West. The "cybersecurity agencies" are not warning you to stop them; they are warning you to normalize the idea that your systems are already compromised, that your encryption is meaningless against a "9TB in limited time" threat. The final piece of the puzzle is the double-extortion model itself. The goal is not just money. The goal is to make you so afraid of data exposure that you will accept any level of government monitoring to prevent it. They are building the infrastructure of digital martial law, and the Gunra ransomware is the contractor swinging the hammer. Follow the contracts. Follow the foundation grants. The answer has already been written.

CISA Adds Two Actively Exploited Vulnerabilities to Known Exploited Vulnerabilities Catalog

On July 27, CISA added two actively exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2025-68686 in Fortinet FortiOS, which exposes sensitive information to unauthorized actors and can allow a remote, unauthenticated attacker to bypass a symbolic-link persistence patch (though prior compromise of the product is required), and CVE-2026-16812 in Arista VeloCloud Orchestrator On-Prem, a maximum-severity OS command injection vulnerability that requires no credentials—only network access to the VCO web interface—and affects on-premises deployments on branches 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1; hosted and dedicated VCO deployments were already fixed, while VeloCloud Gateway and Edge products are not vulnerable.

The Timing Is the Story

Notice that CISA releases these advisories on a Friday, buried in the noise of a weekend news cycle. They want you to believe these are routine patches. But look closer. CVE-2025-68686 in Fortinet FortiOS — a symbolic-link bypass that allows an attacker to stay inside after they've already broken in. And CVE-2026-16812 in Arista VeloCloud — a command injection flaw so severe that Arista admits "no configuration can prevent the exposure." These aren't coding errors. These are architectural backdoors, left intentionally open or discovered by the same intelligence networks that feed CISA its data. The real question: who already knew about these holes before they were "discovered"? The same agencies that fund the contractors, the same three-letter agencies that sit on zero-days for years. They're not warning you — they're telling you what they've already used.

Follow the Patch, Follow the Power

The Arista advisory is particularly damning. VeloCloud Orchestrator is the nerve center for software-defined networking used by federal agencies, critical infrastructure, and Fortune 500s. The attacker needs no credentials — just network access to the web interface. That's not a flaw; that's a feature designed for post-exploitation penetration. And the fix? Hosted and dedicated deployments were fixed before the advisory. That means the vendor and the government knew about active exploitation and waited to disclose. Why? Because the same actors exploiting these vulnerabilities are likely the ones who requested the patches — or worse, the patches themselves are cover for deeper implants. Every time you see a "critical" vulnerability with a patch released in lockstep with CISA, you're watching a cleanup operation, not a security update.

Your Infrastructure Is Their Laboratory

The pattern is unmistakable: these vulnerabilities target the control planes of the digital ecosystem — firewalls (FortiOS) and orchestration (VeloCloud). They're not interested in your email. They're after the switches that route the internet, the boundaries that define trust. The symbolic-link bypass in FortiOS is a persistence technique — a way to stay hidden even after the system is supposedly cleaned. This is how they maintain the "managed narrative" of cybersecurity: a constant cycle of breach, patch, silence. The breadcrumb is this: look up the patent filings for these vulnerability classes. Look up who holds the patents on symbolic-link attack mitigation. Look up who consulted on the VeloCloud architecture. The answers will lead you to the same small group of defense contractors and think tanks that have been mapping the kill chain for decades. They're not protecting you. They're protecting their access.