Ransomware Is Coming Through the Front Door
Click here to view/listen to our blogcast.
When people picture a ransomware attack, they often imagine an employee clicking a malicious link. But attackers do not always need someone inside the organization to make a mistake. Sometimes they enter through a vulnerable system connected directly to the Internet.
On August 10, 2026, CISA, the FBI, and several partner agencies issued a joint warning about Gunra ransomware. This ransomware-as-a-service operation has targeted healthcare, financial services, insurance, government, construction, professional services, and other sectors. Investigators found that Gunra operators exploited known authentication-bypass vulnerabilities in Internet-facing Fortinet FortiOS and FortiProxy devices. After entering, they stole information, moved through internal systems, and encrypted data. Victims then faced double extortion: pay to restore operations and pay to prevent stolen information from being published or sold.
This is not simply a Gunra or Fortinet story. It is a warning about every system exposed to the public Internet.
Why Perimeter Systems Are Different
Firewalls, VPN gateways, remote-access portals, routers, and email-security appliances protect an organization. Because many must remain reachable from the Internet, they are also attractive entry points.
A workstation is usually protected behind several security layers. An Internet-facing device can be scanned and attacked directly from anywhere, around the clock. Attackers do not need to fool an employee or compromise another computer first.
Perimeter equipment therefore needs a more urgent patching and monitoring strategy. Waiting for routine maintenance may be too slow when attackers are already exploiting a vulnerability.
Patch According to Risk, Not Just the Calendar
Not every update carries the same urgency. Organizations should ask:
- Is the system reachable from the Internet?
- Is the vulnerability actively exploited or listed in CISA’s Known Exploited Vulnerabilities catalog?
- Can it bypass authentication or provide administrative access?
- What internal data and systems can the device reach?
- Is the product still supported?
Shortly after the Gunra advisory, CISA added more actively exploited vulnerabilities to its KEV catalog, including one affecting Cisco Secure Firewall products. Vulnerability management must respond to actual threat activity, not just severity scores or convenient schedules.
Patching Is Only Part of the Job
Installing an update closes a vulnerability, but it does not prove attackers were not already inside. Organizations may also need to review logs, administrative accounts, remote-access activity, and configuration changes.
Strong perimeter management should include centralized alerts, multifactor authentication, configuration backups, and restrictions that keep management portals off the public Internet. Unused accounts, ports, and services should be removed, while unsupported equipment should be replaced.
Your Website Is Also a Front Door
A firewall is not the organization’s only public-facing system. Websites, customer portals, web applications, online forms, and content-management systems are also part of its external attack surface.
Even though a website may not provide direct access to the internal network, it can still expose customer information, steal credentials, distribute malware, redirect visitors, and damage the organization’s reputation.
Website security evaluations should examine hosting, software, plugins, administrative access, backups, SSL certificates, DNS settings, and exposed forms. If the platform is unsupported or carrying years of technical debt, another plugin update may not be enough. An overhaul may be safer and more economical.
Limit the Damage When Prevention Fails
The Gunra advisory recommends network segmentation and offline, immutable backups. In one documented attack, criminals deleted backup and archived data from both the primary data center and disaster-recovery center.
Segmentation limits how far an attacker can travel. Offline or immutable backups provide a recovery path ransomware cannot easily erase. Both controls must be tested before an emergency.
How CDML Can Help
CDML Computer Services can help organizations identify and secure the systems attackers see first. Our services include:
- Firewall, VPN, and network-device lifecycle reviews
- Firmware, security-update, and subscription management
- Perimeter monitoring and secure remote-access configuration
- Vulnerability prioritization using current threat intelligence
- Network segmentation and backup-recovery testing
- Website security evaluations and Digital Presence Assessments
- Website remediation or overhaul when necessary
- Incident Response and Disaster Recovery planning
Final Thoughts
Firewalls, websites, and other Internet-facing systems cannot be treated as set-it-and-forget-it technology. Organizations must know which systems are publicly reachable, whether they are supported, and how quickly urgent vulnerabilities will be addressed.
CDML can evaluate your external attack surface, prioritize urgent risks, and build layers of protection that support security and recovery.
Trust is necessary, but trust without verification, monitoring, and limits creates opportunity for attackers. Contact CDML today to schedule a consultation.
Stay safe. Stay informed. Stay compliant.

📞 Contact us here: https://cdml.com/contact/
📚 Read more on our blog: https://cdml.com/blog-2
📺 Listen to our blogcasts: https://www.youtube.com/@CDMLComputerServices


