DFIR Radar[verified]@DFIR_RadarExploit
Gunra ransomware exploits FortiOS auth‑bypass flaws (CVE‑2024‑55591 and CVE‑2025‑24472) to establish superuser accounts before encrypting victim data with ChaCha20+RSA‑4096 and appending .ENCRT.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Gentlemen ransomware used FortiOS CVE‑2024‑55591, ZeroLogon, and PetitPotam to compromise 483 victims worldwide, with detailed vulnerability information and recommended mitigations.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post details that Golden Sherwood’s RaaS is actively exploiting vulnerabilities, including CVE‑2024‑55591 and driver‑based techniques, impacting hundreds of victims worldwide.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post details active exploitation of FortiOS/FortiProxy authentication bypasses by the Gunra ransomware group, outlines tools and techniques used, and provides patch and mitigation guidance.
Gagan Suie[verified]@gagansuieDisclosure
The text announces two authentication bypass CVEs affecting FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) that enable initial access, alongside related credential exposure and SSH control weaknesses.
Scripted World[verified]@Milwyn1Active Exploitation
Gunra ransomware exploits authentication bypass flaws in Fortinet products, with US and South Korean agencies reporting active use; CISA underscores the ongoing threat to critical sectors.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The tweet reports that the Gunra ransomware group is actively exploiting FortiOS/FortiProxy CVE-2024-55591 and CVE-2025-24472 against government and critical infrastructure.
Silent Vector[verified]@gh0st_V3ctbrvActive Exploitation
The tweet outlines Qilin’s use of phishing and VPN exploitation, noting several CVEs, with a clear claim that CVE-2026-50751 is actively exploited this month.