B
今週中
Gunraランサムウェアが、FortinetおよびSchneider Electricの脆弱性を悪用して重要インフラ組織を標的に攻撃を仕掛けています
📌 一言でいうと
Gunraランサムウェアが、FortinetおよびSchneider Electricの脆弱性を悪用して重要インフラ組織を標的に攻撃を仕掛けています。攻撃者はインターネットに公開されているアプライアンスの脆弱性を利用して初期侵入し、データの窃取と暗号化を組み合わせた二重脅迫モデルを用いています。被害者が5〜7日以内に身代金を支払わない場合、窃取したデータがリークサイトで公開される仕組みです。
ℹ️ これは他社で発生した事案の情報です。貴社が当該サービスを利用していない場合は、参考情報としてご確認ください。同様の攻撃手法に対する備えのきっかけとしてもご活用いただけます。
🔍該当判定
- Fortinet社の製品(FortiOS または FortiProxy)を導入し、インターネットに公開している
- Schneider Electric社の製品(PowerLogic P5)を導入し、インターネットからアクセス可能な状態にある
- 自社が「医療・金融・政府機関・非営利団体」のいずれかの業種である
- 社外から社内ネットワークへアクセスするためのVPN装置やゲートウェイにFortinet製品を利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Fortinet FortiOS/FortiProxyおよびSchneider Electric PowerLogic P5の最新パッチを適用し、インターネットに公開されている管理インターフェースの制限を検討してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Fortinet および Schneider Electric 脆弱性を悪用した Gunra ランサムウェアへの対応について
お疲れさまです。Gunra ランサムウェアによる攻撃に関する情報共有です。
■ 概要
Gunra ランサムウェアが、Fortinet および Schneider Electric の製品に存在する脆弱性を悪用して初期侵入し、データの窃取と暗号化を行う二重脅迫攻撃を展開しています。
■ 影響範囲
- Schneider Electric PowerLogic P5 (CVE-2024-5559)
- Fortinet FortiOS および FortiProxy (CVE-2025-24472)
■ 対応手順
1. 対象製品の最新バージョンへのアップデートおよびセキュリティパッチの適用を確認してください。
2. インターネットに公開されている管理インターフェースへのアクセス制限(VPN経由のみにする等)を再確認してください。
3. 不審なデータ転送や特権アカウントの異常な挙動がないかログを監視してください。
■ 参考情報
- CISA および各ベンダー公式アドバイザリ
対応優先度: 高
対応期限: 至急
お疲れさまです。Gunra ランサムウェアによる攻撃に関する情報共有です。
■ 概要
Gunra ランサムウェアが、Fortinet および Schneider Electric の製品に存在する脆弱性を悪用して初期侵入し、データの窃取と暗号化を行う二重脅迫攻撃を展開しています。
■ 影響範囲
- Schneider Electric PowerLogic P5 (CVE-2024-5559)
- Fortinet FortiOS および FortiProxy (CVE-2025-24472)
■ 対応手順
1. 対象製品の最新バージョンへのアップデートおよびセキュリティパッチの適用を確認してください。
2. インターネットに公開されている管理インターフェースへのアクセス制限(VPN経由のみにする等)を再確認してください。
3. 不審なデータ転送や特権アカウントの異常な挙動がないかログを監視してください。
■ 参考情報
- CISA および各ベンダー公式アドバイザリ
対応優先度: 高
対応期限: 至急
Subject: [Security Alert] Gunra Ransomware exploiting Fortinet and Schneider Electric Vulnerabilities
Dear IT/Security Team,
We are sharing intelligence regarding the Gunra ransomware campaign targeting critical infrastructure.
■ Overview
Gunra ransomware is leveraging known vulnerabilities in internet-facing appliances to gain initial access, followed by a double extortion model (data exfiltration and encryption).
■ Affected Products
- Schneider Electric PowerLogic P5 (CVE-2024-5559)
- Fortinet FortiOS and FortiProxy (CVE-2025-24472)
■ Action Items
1. Ensure all affected appliances are updated to the latest patched versions.
2. Restrict access to management interfaces from the public internet (e.g., enforce VPN access).
3. Monitor network logs for unauthorized data exfiltration or anomalous privileged account activity.
■ Reference
- CISA and Vendor Security Advisories
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing intelligence regarding the Gunra ransomware campaign targeting critical infrastructure.
■ Overview
Gunra ransomware is leveraging known vulnerabilities in internet-facing appliances to gain initial access, followed by a double extortion model (data exfiltration and encryption).
■ Affected Products
- Schneider Electric PowerLogic P5 (CVE-2024-5559)
- Fortinet FortiOS and FortiProxy (CVE-2025-24472)
■ Action Items
1. Ensure all affected appliances are updated to the latest patched versions.
2. Restrict access to management interfaces from the public internet (e.g., enforce VPN access).
3. Monitor network logs for unauthorized data exfiltration or anomalous privileged account activity.
■ Reference
- CISA and Vendor Security Advisories
Priority: High
Deadline: Immediate