#StopRansomware: Gunra Ransomware

2026-08-18T20:23:50Zd610eaae5cd0ac7708934951d92fdecc899a4815b65da4cfdee3ddb80e95daf4
CVE-2025-66376CISA advisoryChina-nexusGunraHMIICSIranian-affiliated actorsLAUNDRY BEARPLCRaaSRussian state-sponsoredSCADAZimbra Collaboration Suitecritical infrastructuredouble extortionknown exploited vulnerabilitiesnetwork appliancesnetwork segmentationoffline backupsoperational technologypass-the-cookiepassword sprayingphishingpro-Russia hacktivistsransomware

What happened

CISA advisories describe active threats to government, critical infrastructure, and commercial organizations, including Gunra ransomware-as-a-service with double extortion, Russian state-supported exploitation and phishing targeting Zimbra Collaboration Suite, exploitation of vulnerable networking devices, China-nexus covert infrastructure networks, Iranian-affiliated attacks against internet-exposed PLCs and OT systems, pro-Russia hacktivist attacks on critical infrastructure, and incident-response lessons emphasizing patching, logging, backups, segmentation, and tested response plans. CVE-ิจ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_alerts
Record identifier
d610eaae5cd0ac7708934951d92fdecc899a4815b65da4cfdee3ddb80e95daf4
Enrichment time
2026-08-18T20:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.