Ransomware Is Getting In Through Firewalls and VPNs: What Fort Worth Businesses Should Check
On August 10, 2026, the FBI, CISA, the NSA, and several partner agencies published a joint advisory about a ransomware group called Gunra. Buried in the technical details is the part every Fort Worth business owner should read twice: the group is not getting in through clever phishing emails. It is walking in through firewall and VPN appliances that were never patched. The advisory names two Fortinet vulnerabilities the group has been exploiting to gain privileged access, and it notes the group has found a way to slip past multi-factor authentication once it is inside the device.
This is not a Gunra problem. It is the pattern for how ransomware works in 2026. The front door moved. For years the advice was "train your people not to click bad links," and that advice still matters. But the fastest-growing way attackers get in now is the box sitting in your server closet that connects your office to the internet. This post covers why that shift happened, what the new advisory actually tells you to do, and a plain checklist you can hand to whoever manages your network.
The front door moved
Ransomware stopped knocking on the inbox
The single clearest data point on this comes from Verizon's 2025 Data Breach Investigations Report, which analyzes tens of thousands of real incidents every year. In that report, attacks that exploited vulnerabilities in edge devices and VPNs grew from 3 percent of vulnerability-based break-ins to 22 percent in a single year. That is close to an eight-fold jump. The same report found ransomware present in 44 percent of all breaches it studied, up from 32 percent the year before.
Read together, the story is simple. Ransomware is more common than ever, and the perimeter device is now one of the main ways it arrives. An "edge device" is just the equipment that sits between your internal network and the public internet: your firewall, your VPN gateway, and anything you expose so people can work remotely. These devices are attractive to attackers for a simple reason. They are reachable from anywhere on earth, they run their own software that has to be updated separately from your computers, and in most small businesses nobody is assigned to keep them current. If you want a broader picture of how these pieces fit together, our cybersecurity services page walks through the layers that actually reduce risk.
What the Gunra advisory actually says
The CISA and FBI advisory on Gunra is worth understanding because it is specific, not vague. Gunra first appeared in April 2025 and was built from the source code of Conti, an older ransomware operation whose code leaked publicly in 2022. By early 2026 it had grown into a ransomware-as-a-service operation, which means the people who write the malware rent it out to other criminals who do the breaking in. That model is why the same tool shows up hitting very different kinds of organizations.
The two vulnerabilities the advisory calls out (tracked as CVE-2024-55591 and CVE-2025-24472) both affect Fortinet firewall and VPN products. Once attackers use them to get administrative control of the device, the advisory notes they have been able to tamper with authentication files to get around multi-factor authentication. The government's recommendations are blunt: patch known-exploited vulnerabilities in anything facing the internet, including VPN gateways and any remote-desktop access you have exposed, and segment your network so a single compromised device cannot reach everything else.
We wrote earlier this year about a different group using a similar entry method in our post on Akira ransomware and small business defense. Two different groups, same front door. That is the point.
Why the edge is so easy to miss
The device nobody logs into
Here is the honest reason edge devices go unpatched. A firewall or VPN appliance is supposed to be the thing you set up once and forget. It sits in a closet, a light blinks, traffic flows, and everyone moves on. Unlike a laptop, nobody logs into it every morning, so nobody notices that its firmware is two or three versions behind. Some businesses are still running appliances the manufacturer stopped supporting years ago, which means no more security updates are being written for them at all. A device like that is not protecting your network so much as advertising a way in.
This is exactly the kind of gap that a real endpoint and network management program is built to close: a running inventory of every device, a schedule for firmware updates, and an actual owner responsible for the perimeter. When "who patches the firewall" has no clear answer, the answer in practice is "nobody," and that is what the current wave of ransomware is counting on. It is the same lesson we covered in our piece on using the CISA Known Exploited Vulnerabilities catalog to prioritize what to fix first.
MFA on the VPN is not the finish line
Multi-factor authentication is one of the best security controls a small business can turn on, and every business should have it on remote access. But the Gunra advisory is a useful reminder of what MFA does and does not do. If an attacker exploits a flaw in the VPN device itself and gains administrative control, they can, in some cases, tamper with the device to bypass the login checks entirely. The lock on the door does not help if someone climbs in through the wall.
That does not make MFA pointless. It makes it one layer among several. The devices still have to be patched. Access still has to be monitored so that a strange login from an unusual place gets noticed. End-of-life gear still has to be replaced. MFA plus current firmware plus monitoring is a real defense. MFA on top of a three-year-old unpatched appliance is a false sense of one.
Worried about what is exposed on your network edge? IT Integrations provides managed IT and cybersecurity services for Fort Worth businesses and the surrounding DFW area. Call us at (817) 808-1816 or contact us for a free IT assessment.
The Fort Worth angle
Fort Worth and the surrounding DFW cities are full of exactly the businesses this pattern hits hardest: small and mid-sized operations with a real office, remote or field access, and a firewall someone installed a while back and has not thought about since. The threat groups do not skip a company because it is in Aledo or Weatherford instead of a coastal metro. Ransomware-as-a-service affiliates scan the entire internet for reachable, unpatched devices. Being a 20-person business in Benbrook does not make you invisible. It often makes you a softer target than the enterprise down the road with a full security team.
The local industries we work with each have their own version of this exposure. Construction companies run VPN and remote access so the field can reach project management software and plans from the jobsite, which means the edge is doing real work every day and cannot simply be locked down. If you run crews in the field, our construction IT services page covers how we keep that remote access both usable and defended. Healthcare practices reach electronic medical records remotely, which turns an edge-device breach into a potential HIPAA incident, not just an IT headache. Water utility districts connect remote sites and control systems that were never designed to be exposed to the open internet. In every case, the perimeter device is carrying more weight than it was originally set up to carry, and it needs the same attention as everything else. Businesses out in Weatherford and Parker County tend to run leaner IT setups, which makes an unowned firewall an even more common find.
What we see when we audit a new client's edge
After 20 years of taking over environments from other providers, the findings at the network edge repeat so often we could almost predict them before we plug in. This is not a knock on anyone. It is what happens when the perimeter has no clear owner.
The firewall or VPN appliance is usually running firmware that is several releases behind current, sometimes a major version behind. Remote access frequently has MFA on some accounts but not all, or on the main VPN but not on a secondary access method someone set up years ago and forgot. We regularly find remote desktop access exposed directly to the internet, which is one of the most reliable ways ransomware gets a foothold. Occasionally the firewall itself has reached end of life and no longer receives security updates at all, still sitting in the rack right up until it becomes the way in. And almost always, when we ask who is responsible for updating the firmware, there is a pause, because the honest answer is that it fell between the cracks.
None of this means the previous setup was careless. Edge devices are genuinely easy to lose track of. The fix is not blame, it is ownership: someone whose job is to know what is exposed and keep it current. That is a large part of what a managed IT relationship is supposed to buy you, and it is the first thing we check when we run a free assessment on a new environment.
A practical edge checklist
You do not need us to start on this. Here is the short version of what actually reduces your exposure at the perimeter, in plain order of priority.
First, make a list of every device and service that is reachable from the internet: firewalls, VPN gateways, any remote desktop access, and any appliance with a public address. You cannot protect what you have not written down. Second, find out the current firmware version on each one and compare it to what the manufacturer has published, then update anything behind. Third, put multi-factor authentication on every form of remote access, with no exceptions for "just this one account." Fourth, close any remote desktop access that is exposed directly to the internet and route it through a monitored VPN instead. Fifth, identify anything the manufacturer no longer supports and plan its replacement, because unsupported gear cannot be secured no matter how carefully you configure it. Sixth, segment the network so that a compromised edge device cannot reach your servers and backups in one hop. Finally, make sure someone is actually watching the logs, so a login from an unexpected place at an unexpected hour gets seen while it still matters.
If that list produced a few honest "I am not sure" answers, that is a good reason to get a second set of eyes on the perimeter.
Frequently Asked Questions
We have a firewall. Isn't that the whole point of having one?
A firewall is essential, but it is a piece of software running on hardware, and like all software it has flaws that get discovered over time. The manufacturer releases updates to fix those flaws. If the firewall is never updated, it keeps running the old code with the known holes in it, and those holes are exactly what advisories like the Gunra one describe attackers using. So the honest answer is that a firewall protects you only as well as it is kept current. An unpatched firewall is not a wall, it is a door with a published key. Owning one is the start. Maintaining it is the actual protection.
How often should firewall and VPN firmware be updated?
There is no single number, because it depends on the vendor's release schedule and on whether a given update fixes an actively exploited flaw. The practical rule is this: routine firmware updates should be reviewed and applied on a regular cadence, and any update that addresses a vulnerability appearing on CISA's Known Exploited Vulnerabilities catalog should be treated as urgent and applied quickly, not on the normal schedule. That is why the "we update everything once a quarter" approach falls short. Attackers do not wait for your quarter to end. The point is to have a defined cadence for the routine work and a fast lane for the emergencies.
We already use MFA on our VPN. Are we covered?
MFA is one of the most valuable controls you can have, and you should keep it. But the recent advisory is a reminder that it is not a complete defense by itself. When an attacker exploits a flaw in the VPN device and gains administrative control, they can, in some documented cases, tamper with it to get around the login checks. MFA still stops the large majority of credential-based attacks, but it works best when the device underneath it is also patched and monitored. Think of MFA, current firmware, and active monitoring as three parts of one defense, not three things you pick from.
Are small Fort Worth businesses really targeted, or is this a big-company problem?
Small businesses are targeted, and the reason is mechanical rather than personal. Ransomware-as-a-service affiliates use automated tools to scan the entire internet looking for devices with known, unpatched vulnerabilities. The scan does not know or care whether the device belongs to a hospital system or a five-person office in Crowley. It just finds reachable, vulnerable devices and flags them. In many ways a smaller business is at higher risk, because it is less likely to have someone whose job is to keep the perimeter patched. The size of the company is not what protects it. The state of its edge devices is.
We are a healthcare practice. What does an edge-device breach mean for HIPAA?
It can mean a great deal. If attackers gain access through your firewall or VPN and reach systems that hold protected health information, that is a security incident that likely triggers your breach notification obligations under HIPAA. The government advisory specifically notes these groups steal data before they encrypt it, which for a healthcare practice means patient information potentially leaving the building. That is why we treat the network edge as a compliance issue for our healthcare clients, not just a technical one. Keeping the perimeter patched is part of the security risk management the HIPAA Security Rule expects you to be doing in the first place.
Next Steps
The takeaway from this month's advisory is not that a new ransomware group exists. New groups appear constantly. The takeaway is that the way in has shifted toward the devices at the edge of your network, and those devices are the ones most likely to be quietly out of date. The good news is that this is a fixable, boring problem. Inventory what is exposed, patch it, put MFA everywhere, retire what is unsupported, segment the network, and watch the logs. None of that is glamorous, and all of it works.
Want to know what is exposed on your network before someone else finds it? IT Integrations provides managed IT, cybersecurity, and network management for Fort Worth businesses and the surrounding DFW metro. Call (817) 808-1816 or schedule a free IT consultation today.