Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Gunra ransomware exploiting Fortinet VPN flaws to bypass MFA — six-agency advisory

Ransomware Gang Bypasses MFA on Fortinet VPNs — What to Check Now

A ransomware group called Gunra is actively exploiting known Fortinet VPN vulnerabilities to break into business networks — and they’ve found a way to bypass multi-factor authentication while they’re at it. Six government agencies, including the FBI, CISA, and the NSA, issued a joint advisory about the campaign in August.

This matters for Australian businesses because Fortinet is one of the most commonly deployed firewall platforms in the local SMB market. The vulnerabilities being exploited — CVE-2024-55591 and CVE-2025-24472 — aren’t new. They were disclosed in early 2025 and patches have been available for over a year. But plenty of appliances remain unpatched, and Gunra is taking advantage.

What makes this campaign different is the MFA bypass. After gaining access through the VPN flaw, the attackers modified authentication files on their victim’s VDI portal server so that a specific one-time password they controlled would always work. That’s not a brute-force attack or a phishing trick — it’s a persistent backdoor that survives password resets and keeps MFA switched on in name only. In one case, they also deleted backups at both the primary data centre and DR site before deploying ransomware.

We see a pattern across our Australian client base: businesses invest in MFA and assume the perimeter is handled. But if the device sitting in front of your MFA is itself compromised, none of that matters. It’s a reminder that patching your firewall firmware is just as critical as patching your servers and workstations.

Three things to do this week:

  1. Check your FortiGate firmware. If you’re running FortiOS or FortiProxy, confirm you’re on a version that patches CVE-2024-55591 and CVE-2025-24472. Both are in CISA’s Known Exploited Vulnerabilities catalogue.
  2. Review VPN and VDI authentication logs. Look for unusual login patterns, especially successful authentications from unexpected locations or at odd hours.
  3. Test your backups. Gunra specifically targets backup infrastructure. Make sure your backups are offline or immutable — not just on a NAS sitting on the same network.

If you’re not sure whether your Fortinet appliances are up to date, or you want a second set of eyes on your VPN configuration, get in touch with our cybersecurity team.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →