// Microsoft 365HIGH
FBI and CISA disclosed that Gunra ransomware actors are exploiting Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472) to gain initial network access, then conducting stealthy lateral movement and large-scale data exfiltration from Microsoft 365 services, particularly OneDrive and SharePoint. The group uses authentication bypass techniques, disables MFA, and operates primarily during off-hours to evade detection. Ransom demands typically start in the tens of millions.
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infr(opens in a new tab)
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco(opens in a new tab)
- Yehey.com - Gunra Ransomware Exploits Fortinet Vulnerabilities t(opens in a new tab)
// Get alerts for Microsoft 365