DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post reports that Gunra ransomware actively uses two FortiOS authentication‐bypass CVEs to create superuser accounts and then encrypt victim files.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The report details global exploitation of FortiOS/FortiProxy auth bypass vulnerabilities by the Gunra ransomware group, providing rich operational insights and actionable patch recommendations.
Gagan Suie[verified]@gagansuieGeneral
The tweet lists several authentication and credential exposure vulnerabilities in Fortinet products but does not provide any PoC, exploit, patch information, or evidence of active exploitation.
Scripted World[verified]@Milwyn1Active Exploitation
The passage announces that the Gunra ransomware group is actively exploiting authentication bypass vulnerabilities in Fortinet's FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) to gain admin access, with agencies highlighting this ongoing threat.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Gunra ransomware teams are actively exploiting CVE‑2024‑55591 and CVE‑2025‑24472 in FortiOS/FortiProxy against government and critical infrastructure, with no patch or PoC details disclosed.
SecureChap[verified]@SecureChapExploit
The post details how Gunra ransomware leverages CVE‑2024‑5559 and CVE‑2025‑24472, exploiting weak key derivation and abusing widespread tools like Impacket and secretsdump, with evidence of active use and large-scale exfiltration.
Jim Johnson[verified]@jvjinfinityActive Exploitation
CISA reports a threat group targeting hospitals via Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472), prompting a call for patching and risk assessment.
SHORT INFO[verified]@ShortInfoNewsActive Exploitation
CISA and other U.S. agencies warn that Gunra ransomware affiliates are actively exploiting two Fortinet CVEs (CVE-2024-55591, CVE-2025-24472) to breach healthcare, financial, and government networks worldwide.