Your Perimeter Has an Open Door Policy
# Your Perimeter Has an Open Door Policy
Microsoft just dropped its August Patch Tuesday update, fixing 421 CVEs. In the middle of that noise is CVE-2026-68820, a kernel-mode driver flaw already being used in the wild. Most security teams will spend their week staring at that number, 421, and wondering which ones to prioritize based on who's screaming loudest in Slack. They'll ignore the fact that while they're worrying about the next zero-day, Gunra is currently walking through the front door of critical infrastructure using keys that were handed out years ago.
Gunra has appeared in 13 stories this week. That isn't a high number for a global campaign, but it's enough to show a pattern. They aren't inventing new ways to break into networks. Instead, they're exploiting known vulnerabilities in Fortinet and Schneider Electric products. This is the most boring kind of breach: the one where the vendor provided the fix, the documentation was clear, and the victim simply chose not to apply it.
The industry loves to call these "sophisticated attacks." It's a convenient term. If an intrusion is "sophisticated," the CISO can tell the board that they were hit by a ghost, a force of nature that no amount of preparation could have stopped. But there is nothing sophisticated about exploiting a known bug in a perimeter device. It's just basic housekeeping.
Gunra's targets are currently concentrated in sectors where "uptime" is treated as a religious dogma that supersedes security updates. Healthcare and Energy & Utilities are sitting at #3 and #4 on the sector target list, with healthcare alone seeing 103 stories this week. In these environments, the argument is always the same: we can't take the system offline for a patch because it might disrupt service.
That logic is fundamentally broken. You cannot claim to prioritize "uptime" while leaving your edge gateway exposed to a public exploit. A ransomware lockout lasts significantly longer than a scheduled reboot.
The victim statements in these cases follow a predictable script. They speak of "unauthorized access" and "complex threats." They avoid mentioning the specific version numbers of the compromised hardware. They won't tell you that they were running a FortiOS version from 2023 when the fix was released months prior. When a vendor's advisory says "Update to vX.Y.Z immediately," and the victim remains on vX.W, the breach isn't an accident. It's a choice.
Getting hit is common. Handling it badly, by pretending the attack was an act of God rather than a failure of version control, is where the real negligence begins.
The cost here isn't just the ransom demand or the immediate cleanup fee. The second-order effect is more insidious. When Gunra hits a Schneider Electric-managed system in a utility plant, they aren't just encrypting files; they're compromising the trust chain for every downstream customer. If a water treatment facility goes dark because of an unpatched PLC, the fallout moves from the server room to the municipal pipes. The insurance companies will eventually stop paying out for "known vulnerabilities." We're already seeing this in other sectors; it's only a matter of time before "failure to patch" becomes a standard exclusion clause in cyber policies.
This rhymes with the 2017 WannaCry disaster, where thousands of organizations were crippled by an exploit (EternalBlue) for which a patch had existed for two months. The parallel is the reliance on legacy systems and the fear of the reboot. Where it differs today is the target. In 2017, we were talking about office PCs and medical records. Now, we're talking about the hardware that keeps the lights on and the water running.
The Technology sector remains the primary target, ranking #1 of 17 this week with 424 stories. This is expected; tech companies are the staging grounds for larger leaps. But Gunra isn't interested in the tech for the sake of the tech. They're using these vulnerabilities as a bridge to reach the physical world.
Some will argue that patching critical infrastructure is different from patching a laptop. They'll point to "industrial stability" and the risk of bricking a device that controls a turbine. This is a fair point, but it's an argument for better architecture, not for ignoring patches. If you cannot patch a device because it's too fragile, that device should not be reachable from the public internet. It should be behind a series of air-gaps or strictly controlled jump boxes. Instead, organizations are putting these fragile, unpatched devices on the wire and then acting surprised when someone finds them.
We also have to look at the sheer volume of data being lost elsewhere as a distraction. DentaQuest just exposed records for 15 million people. It's a massive number that dominates the headlines because it's easy to visualize. But 15 million leaked dental records, while a privacy nightmare, doesn't shut down a power grid. We shouldn't let the scale of data breaches blind us to the severity of infrastructure intrusions.
The "critical" label is thrown around far too often. A vulnerability isn't critical because a CVSS score says 9.8; it's critical when there is a working exploit and a target that refuses to update. Gunra has found plenty of those targets.
If you're managing a perimeter today, don't look at the "sophistication" of the attackers. Look at your version numbers. If they don't match the latest stable release from your vendor, you aren't "managing risk." You're just waiting for Gunra to find your IP address.
The real question is whether we'll actually move toward a model where security updates are mandatory for critical infrastructure, or if we'll keep pretending that an unpatched firewall is an acceptable trade-off for uptime until the lights actually go out.
◼