Gunra Ransomware Targets Global Critical Infrastructure [Prime Cyber Insights]
I’m Aaron Cole, and this is Prime Cyber Insights for August 11th, 2026. Joining us today is Chad Thompson, a Director-level AI and security leader with a systems-level perspective on automation, enterprise risk, and operational resilience. Chad, it is great to have you. <br/><i>acting_description:</i> professional, steady, leading <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.3 Thanks, Aaron. We’re starting today with a joint advisory from CISA and South Korean authorities regarding Gunra ransomware. They’re observing a double-extortion campaign targeting critical infrastructure, specifically exploiting CVE 2024 5559 in Schneider Electric PowerLogic P5 and CVE 2025 24472 in Fortinet appliances. <br/><i>acting_description:</i> engaged, measured, clear <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 The technical precision of these attacks is notable, Lauren. Gunra is moving laterally using Impacket libraries and exfiltrating terabytes of data to M-E-G-A before encryption. They’ve even been seen manipulating SSL-VPN traffic to intercept V-D-I session cookies, effectively bypassing MFA by tampering with the authentication processing files. <br/><i>acting_description:</i> analytical, direct, authoritative <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 It highlights a recurring theme: the friction between secure defaults and legacy compatibility. That leads us to the 'Pass-ta-key' research out of Palo Alto Networks. Chad, the research suggests that malware can extract passkeys from the Google Password Manager on Windows because they aren’t always stored in the TPM. How does this impact our view of passkeys as a phishing-proof solution? <br/><i>acting_description:</i> responsive, observant, composed <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Lauren, it is a critical distinction. The FIDO2 specification doesn’t actually mandate TPM storage because developers prioritize cross-device syncing. On mobile platforms, sandboxing is aggressive enough to protect those keys, but Windows lacks that same granular isolation by default. If a Windows machine is compromised at the agent level, the passkeys stored in software-based vaults become accessible to the attacker. <br/><i>acting_description:</i> knowledgeable, precise, technical <i>speed:</i> 0.96 <i>trailing_silence:</i> 0.2 From a systems-risk perspective, this doesn’t make passkeys insecure, but it does change the threat model. We’re seeing third-party managers like 1Password and Google move toward end-to-end encrypted cloud blobs for Windows specifically to mitigate this. For practitioners, the takeaway is that passkeys solve for phishing, but they don't absolve us of the need for robust endpoint detection and response. <br/><i>acting_description:</i> focused, objective, explanatory <i>speed:</i> 0.97 <i>trailing_silence:</i> 0.2 We also have to look at the automation aspect. As we see in the Cloudflare data reporting a 519 percent surge in terabit-scale DDoS attacks, the scale of automated threats is outstripping manual defense. Whether it’s credential harvesting via Pass-ta-key or massive network-layer floods, the reliance on hardware-level roots of trust and automated mitigation is no longer optional for enterprise resilience. <br/><i>acting_description:</i> deliberate, informative, neutral <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.5 Excellent context, Chad. Thank you for that analysis. Aaron, shifting from identity to the software supply chain, we have a significant development with BdThemes. Wordfence is reporting that attackers poisoned a remote J-S-O-N data stream used for promotional banners in WordPress plugins to inject rogue admin accounts. <br/><i>acting_description:</i> appreciative, crisp, attentive <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Exactly, Lauren. This is stealthy because it doesn’t require a plugin update. By gaining write access to a vendor’s storage bucket, the actors injected malicious JavaScript that runs whenever an admin logs into the dashboard. It even hooks into database queries to hide the rogue accounts from the agent list. It is a high-impact bypass of traditional file-integrity monitoring. <br/><i>acting_description:</i> controlled, insightful, firm <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 And the infrastructure targets keep coming. Polish C-E-R-T just detailed how the Electrum threat group used a private Access Point Name to breach a small energy plant. They moved laterally through a cellular router to shut down a steam turbine. It’s a novel vector, using a private mobile gateway to circumvent air-gapped logic. <br/><i>acting_description:</i> grave, factual, alert <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.4 It’s a reminder that private doesn’t mean secure without client isolation. Managing these distributed OT assets is becoming the front line of grid resilience. That is our briefing for today. I’m Aaron Cole. <br/><i>acting_description:</i> serious, cautionary, conclusi

