CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
The advisory outlines Gunra’s latest attack methods and urges organizations to tighten access controls, patch systems and use multi-factor authentication.
- CISA, the FBI, and the Korean National Police Agency issued a joint advisory on Monday regarding the Gunra ransomware, which exploits vulnerabilities in internet-facing devices to target critical infrastructure organizations.
- Emerging in 2025, the Gunra variant evolved into a ransomware-as-a-service operation, with collaboration between the group and North Korean government-linked hackers dating back to at least 2024.
- Operating under the alias Golden Community, the group employs a double-extortion model, encrypting data while threatening to publish stolen information on a Tor leak site if ransom remains unpaid.
- Police on Tuesday urged domestic companies and institutions to restrict external access, apply security patches, and implement multi-factor authentication to block initial infiltration attempts.
- According to the joint advisory, Gunra's global scope spans Africa, the Americas, Europe, the Middle East, and Asia-Pacific, impacting diverse sectors including finance, healthcare, and manufacturing.
15 Articles
15 Articles
Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
US cyber agencies are warning critical infrastructure operators to patch their internet-facing kit after Gunra ransomware affiliates were spotted exploiting known vulnerabilities to break into networks. Gunra first surfaced in 2025 and has wasted little time expanding. CISA, the FBI, NSA, Secret Service, and partner agencies in the US and South Korea say it now operates as ransomware-as-a-service, with affiliates attacking organizations worldwid…
As the threat of Gunra ransomware grows, South Korean and U.S. authorities have issued a joint security advisory. To counter double-dagger attacks that extort money after stealing internal corporate data, they urged adherence to basic security practices, such as VPN control and multi-factor authentication, and requested that any infections be reported to the police.
(Seoul = Yonhap News) Reporter Han Ji-eun = The police [discuss] the latest attack patterns of the 'GUNRA' ransomware, which has recently been expanding its attacks against domestic and international institutions and companies...
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations. Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and constructio…
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







