Back Ground.News CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks. Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwid…
Police on Tuesday called on domestic companies and institutions to strengthen their security against a ransomware variant named "Gunra," as they jo...
As the threat of Gunra ransomware grows, South Korean and U.S. authorities have issued a joint security advisory. To counter double-dagger attacks that extort money after stealing internal corporate data, they urged adherence to basic security practices, such as VPN control and multi-factor authentication, and requested that any infections be reported to the police.
(Seoul = Yonhap News) Reporter Han Ji-eun = The police [ ] the latest attack patterns of the 'GUNRA' ransomware, which has recently been expanding its attacks against domestic and international institutions and companies...
U.S. and South Korean cyber agencies warned Monday a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations. Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and constructio…
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
