[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-us-and-south-korean-agencies-warn-on-gunra-ransomware-scheme":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},4892,"us-and-south-korean-agencies-warn-on-gunra-ransomware-scheme","US and South Korean Agencies Warn on Gunra Ransomware Scheme","Federal agencies detail how the Conti-derived ransomware-as-a-service recruits penetration testers as paid access brokers into corporate networks.","Six government agencies just detailed how the Gunra ransomware gang breaks in, and it's now recruiting the very people paid to stop it.\n\nCISA, the FBI, the NSA, the Secret Service, the Pentagon's Cyber Crime Center, and South Korea's National Police Agency published a joint advisory on Gunra ransomware, a double-extortion strain built on leaked Conti source code that first surfaced in April 2025. Since January 2026, Gunra has run as a ransomware-as-a-service operation, selling affiliates a management panel, a ransomware builder, and cross-platform payloads. Affiliates typically get in by exploiting known authentication-bypass bugs in Fortinet VPN gear, tracked as CVE-2024-55591 and CVE-2025-24472, or by abusing exposed SSH access on VPN gateways. Once inside, they steal data before encrypting it, then give victims five to seven days to pay through a Tor negotiation portal before threatening to leak everything.\n\nThe advisory's most notable detail is that Gunra is now paying penetration testers and self-described ethical hackers a cut of the ransom to sell it initial access to networks they were hired to secure. That blurs a line the security industry depends on staying bright, and it means the next insider risk at a company could be a contractor with legitimate credentials rather than a phishing victim. It's also a reminder that the Fortinet bugs patched back in 2024 and 2025 are still the entry point of choice for ransomware crews more than a year later.\n\nSix agencies across two governments signing one advisory says less about Gunra's technical sophistication than about how many mid-sized breaches it's already caused.","[\"ransomware\",\"cisa\",\"vpn-vulnerabilities\",\"cybercrime\"]","2026-08-10T12:00:00.000Z","2026-08-14T05:57:45.204Z","2026-08-14T05:57:57.025Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"publisher-r1","publisher",1,"The closing line references 'six government agencies across two countries' co-signing 'one advisory,' but no such advisory, agency count, or country count is established anywhere earlier in the body, making it an unsupported\u002Finconsistent fact.","resolved","security",[32,33,34,35],"ransomware","cisa","vpn-vulnerabilities","cybercrime",[37],{"name":38,"url":39},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fcybersecurity-advisories\u002Faa26-222a",0,{"sections":42},[43,48,51,56,61,66,71,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",435,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]