Find notable cyber news and cases, enriched with sources, timelines, and signals.

Gunra ransomware CVE exploitation and double-extortion activity

Malware Activity
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Gunra ransomware activity is actively exploiting CVE-2024-55591 and CVE-2025-24472 to reach internet-facing devices, putting victim systems and data at immediate risk. Once inside, the operators use double extortion to steal data and encrypt files. Victims are threatened with publication through a Tor-based portal if ransom is not paid within five to seven days. The activity spans critical infrastructure and multiple sectors worldwide.

Related Happenings

Gunra ransomware mitigation advisory (CISA/FBI/partners)

Advisory/Mitigation
H score38 First: 10.08.2026 15:00 Last: 10.08.2026 15:00 Sources 1

How related: The advisory provides tailored detection guidance, indicators of compromise (IOCs), recommended actions if potential compromise is detected, and mitigation recommendations aligned to Cross-Sector Cybersecurity Performance Goals (CPGs).

About this happening: CISA, FBI, DC3, NSA, USSS, and KNPA issued #StopRansomware: Gunra Ransomware to give organizations detection guidance, IOCs, and mitigation recommendations for G...

Luxury jewelry retailer hit by ransomware attack

Incident
H score45 First: 07.07.2026 16:27 Last: 07.07.2026 16:27 Sources 1

About this happening: A luxury jewelry retailer suffered a help-desk social engineering intrusion in May 2025 that led to account takeover and the theft of at least 77 gigabytes of data...

Silent Ransom Group shifts from Conti-linked ransomware participation to standalone data-theft extortion

Threat Actor Meta
H score21 First: 07.06.2026 17:09 Last: 07.06.2026 17:09 Sources 1

About this happening: Silent Ransom Group (UNC3753) is a standalone data-theft extortion actor that has operated separately since 2022 after the Conti shutdown, using stolen data and le...

Storm-1175 high-velocity exploit campaign

Campaign
H score59 First: 06.04.2026 19:56 Last: 06.04.2026 19:56 Sources 1

About this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...

Aleksey Olegovich Volkov sentenced in Yanluowang ransomware case

Law Enforcement
H score35 First: 24.03.2026 15:06 Last: 24.03.2026 15:06 Sources 1

About this happening: The Justice Department said Aleksey Olegovich Volkov was sentenced to 81 months in prison for serving as an initial access broker in Yanluowang ransomware atta...

Timeline

  1. 10.08.2026 15:00 2 articles · 9h ago

    CISA and partners warn on Gunra ransomware exploiting CVE-2024-55591 and CVE-2025-24472

    Initial Disclosure

    CISA, FBI, DC3, NSA, USSS, and KNPA released a joint Cybersecurity Advisory on Gunra ransomware, describing it as a ransomware-as-a-service variant used by affiliates to target critical infrastructure sectors and organizations worldwide, including healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. The advisory says Gunra actors gain initial access by exploiting CVE-2024-55591 and CVE-2025-24472 in internet-facing devices, then use double extortion with data exfiltration, data encryption, and Tor-based publication threats if the victim does not pay the ransom within five to seven days.

    Show sources