The Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and their government partners have released additional technical detail on how Gunra ransomware actors break into victim networks. According to the latest joint advisory, Gunra affiliates are gaining their initial foothold through two known vulnerabilities in internet-facing devices, the kind of edge hardware, VPN gateways, firewalls, and remote access appliances, that sit at the perimeter of nearly every organization's network.

This is a follow-up to earlier warnings about the ransomware-as-a-service operation, which agencies previously flagged for targeting the healthcare sector and for running an aggressive double extortion scheme that combines data theft with file encryption. The new guidance zeroes in on the mechanics of the intrusion itself, giving defenders a clearer picture of exactly where to focus their attention.

The Vulnerabilities Gunra Actors Are Exploiting

According to the advisory, Gunra actors are not relying on novel zero-day exploits. Instead, they are exploiting two already-known vulnerabilities in internet-facing devices, the software and appliances that organizations expose to the public internet to enable remote work, site-to-site connectivity, or external services. This pattern is consistent with how most ransomware-as-a-service affiliates operate: rather than investing in expensive exploit development, they scan the internet for unpatched systems and walk through doors that should have already been closed. The lesson for defenders is straightforward. Known vulnerabilities remain dangerous for a long time after they are disclosed, because patching cycles inside real organizations are often slower than the pace at which attackers weaponize public exploit code.

How Gunra Gains a Foothold Once Inside

Once Gunra affiliates exploit one of these entry points, they use that access to move deeper into the network. Internet-facing devices like VPN concentrators and firewalls are attractive targets precisely because compromising them often grants a level of trust that internal systems assume is legitimate. From there, actors can establish persistence, harvest credentials, and begin mapping the network in preparation for the data theft and encryption stages that define Gunra's double extortion model. Because the initial compromise happens at the network edge, organizations that treat perimeter devices as "set and forget" infrastructure are especially exposed. These devices are often deployed once, configured for uptime rather than security, and left running for years without a firmware or patch review.

Patch and Configuration Steps to Close the Gap

The advisory's core recommendation is one that applies broadly across ransomware campaigns, not just Gunra: patch internet-facing devices promptly and prioritize known, actively exploited vulnerabilities over routine updates. IT and security teams should maintain a current inventory of every device exposed to the internet, including VPN gateways, firewalls, and remote access tools, and confirm each one is running a supported, updated version. Where patching cannot happen immediately, organizations should consider taking the affected service offline or restricting access until a fix is applied. Multi-factor authentication on all remote access points, combined with logging and alerting on unusual login activity, adds another layer of resistance even if a device has an unpatched flaw.

Why VPN Access Control and Network Segmentation Limit Ransomware Spread

Even with disciplined patching, no organization can guarantee zero exposure at all times. That's why access control and segmentation matter as much as the initial fix. VPN access should be scoped tightly, with users granted only the network segments they actually need rather than broad access to the entire environment. Segmenting networks so that a compromised edge device cannot reach sensitive systems, backup servers, or domain controllers directly can be the difference between a contained incident and a full-scale ransomware event. These controls do not prevent every intrusion, but they slow attackers down and buy defenders time to detect and respond before encryption and data exfiltration occur.

What This Means For You

For IT administrators and security teams, this advisory is a reminder that ransomware groups like Gunra continue to succeed by exploiting the basics: unpatched systems and overly permissive network access, not sophisticated novel attacks. Effective Gunra ransomware protection starts with an honest audit of every device your organization exposes to the internet. If you operate in healthcare or another sector previously named in Gunra advisories, the urgency is even higher, since the group has already shown a willingness to target those environments specifically.

Actionable Takeaways

Organizations should inventory all internet-facing devices, including VPN gateways and firewalls, and confirm patch status against known vulnerabilities. Restrict remote access with multi-factor authentication and least-privilege VPN permissions. Segment networks so a single compromised device cannot expose backups or critical systems. Review the earlier CISA, FBI, and NSA advisories on Gunra's healthcare targeting and double extortion tactics for the full technical indicators and sector-specific guidance needed to build a complete defense plan.