Gunra, a ransomware-as-a-service operation derived from leaked Conti code, has breached at least 51 organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific, hitting hospitals, government agencies and financial institutions, with most documented ransom demands exceeding $10 million. A joint advisory from six U.S. and South Korean government agencies said the group mainly gained access by exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472, though investigators also documented cases involving default SSL-VPN credentials and stolen session cookies. The alert also highlighted a separate March 2026 finding from Breakglass Intelligence that Gunra's Linux encryptor contains a cryptographic weakness: files with the .GNRA extension may be recoverable without payment if timestamps are preserved, because the malware uses a weak random-number process to generate encryption material. The advisory urges organizations to patch internet-facing systems, rotate credentials, isolate backups, audit MFA (multi-factor authentication) integrity and avoid rebooting or altering encrypted Linux files before incident responders assess recovery options.