PULSE the living trend engine
↓ Cooling Business

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA and international security agencies warn of a surge in ransomware attacks targeting Microsoft SharePoint and critical infrastructure.

6sources
6articles
4velocity
-74%since first seen
2h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a flaw within Microsoft SharePoint is currently being exploited in ransomware attacks. Concurrent reports indicate that a group known as the Gunra ransomware gang is specifically targeting critical infrastructure. This group is utilizing various vulnerabilities to breach networks, including flaws associated with Schneider Electric and Fortinet products, to facilitate their ransomware deployments. Coverage of these threats is being driven by a mix of government agencies and cybersecurity news outlets. BleepingComputer reported the specific CISA warning regarding Microsoft SharePoint, while The Hacker News detailed the Gunra ransomware gang's use of Fortinet and Schneider Electric flaws.

The Record from Recorded Future News highlighted the collaborative warnings issued by the FBI and South Korea regarding the targeting of critical infrastructure. Additionally, a LinkedIn alert noted that zero-day vulnerabilities in SonicWall SMA1000 are being exploited to breach enterprise networks. This series of events underscores a coordinated effort by security organizations to defend against sophisticated actors. The National Security Agency (NSA) joined the FBI and other partners in releasing formal guidance designed to help organizations defend against Gunra ransomware. The involvement of both the NSA and FBI, alongside international cooperation from South Korea, indicates the high stakes involved when critical infrastructure is targeted by ransomware gangs.

These attacks often rely on exploiting known or zero-day flaws in enterprise hardware and software to gain initial access. Future developments to monitor include the release of further defense guidance from the NSA and FBI as they continue to track the Gunra ransomware gang. Organizations using Microsoft SharePoint, Fortinet, Schneider Electric, and SonicWall SMA1000 systems are the primary focus of current security warnings. Coverage does not yet specify if patches for all mentioned flaws have been deployed, but the emphasis remains on the active exploitation of these specific vulnerabilities to breach enterprise and critical infrastructure networks.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 2h ago.

Quick answers

Which software flaw did CISA warn is being used in ransomware attacks?

CISA warned that a flaw in Microsoft SharePoint is now being exploited in ransomware attacks.

Which agencies released guidance to defend against Gunra ransomware?

The NSA joined the FBI and other partners in releasing guidance to defend against Gunra ransomware.

What other hardware flaws are being exploited by the Gunra gang?

The Gunra ransomware gang is exploiting flaws in Fortinet and Schneider Electric to breach networks.

Coverage (6)

Topics

Related trends