#StopRansomware: Gunra Ransomware
2026-08-18T20:23:50Z•d610eaae5cd0ac7708934951d92fdecc899a4815b65da4cfdee3ddb80e95daf4
CVE-2025-66376CISA advisoryChina-nexusGunraHMIICSIranian-affiliated actorsLAUNDRY BEARPLCRaaSRussian state-sponsoredSCADAZimbra Collaboration Suitecritical infrastructuredouble extortionknown exploited vulnerabilitiesnetwork appliancesnetwork segmentationoffline backupsoperational technologypass-the-cookiepassword sprayingphishingpro-Russia hacktivistsransomware
What happened
CISA advisories describe active threats to government, critical infrastructure, and commercial organizations, including Gunra ransomware-as-a-service with double extortion, Russian state-supported exploitation and phishing targeting Zimbra Collaboration Suite, exploitation of vulnerable networking devices, China-nexus covert infrastructure networks, Iranian-affiliated attacks against internet-exposed PLCs and OT systems, pro-Russia hacktivist attacks on critical infrastructure, and incident-response lessons emphasizing patching, logging, backups, segmentation, and tested response plans. CVE-ิจ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_alerts
- Record identifier
- d610eaae5cd0ac7708934951d92fdecc899a4815b65da4cfdee3ddb80e95daf4
- Enrichment time
- 2026-08-18T20:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.