// Alert

Microsoft 365 threat report

FBI and CISA disclosed that Gunra ransomware actors are exploiting Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472) to gain initial network access, then conducting stealthy lateral movement and large-scale data exfiltration from Microsoft 365 services, particularly OneDrive and SharePoint. The group uses authentication bypass techniques, disables MFA, and operates primarily during off-hours to evade detection. Ransom demands typically start in the tens of millions.

// Get alerts for Microsoft 365