Urgent.News

What's breaking now, across thousands of outlets.

Tech

Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About

Internet-Exposed RDP Is Still the Ransomware On-Ramp the Gunra Advisory Warns About The Gunra ransomware advisory published on 10 August 2026 lists three key actions for defenders. The first is to prioritise patching known exploited vulnerabilities in internet-facing systems, and it names virtual private network gateways and RDP-exposed infrastructure in the same breath [1]. The pairing is…

The Gunra ransomware advisory issued on August 10, 2026, identifies internet-exposed Remote Desktop Protocol (RDP) as the primary entry point for ransomware attacks. The advisory warns that prioritising patching vulnerable systems is crucial, specifically mentioning virtual private network (VPN) gateways and RDP-exposed infrastructure.

Gunra's initial access often involves exploiting known vulnerabilities in internet-facing devices, such as firewall and VPN appliances (CVE-2024-55591 and CVE-2025-24472). Once inside, attackers use tools like Impacket's psexec.py and smbclient.py to move laterally across networks using the Server Message Block (SMB) protocol, and in some cases, they gain access to internal virtual desktop infrastructure environments via RDP.

The advisory highlights that RDP, when exposed to the internet, serves as both an entry point and a means for lateral movement within a network due to its ability to admit legitimate administrators and attackers alike. While ZoomEye observations show a vast number of exposed RDP endpoints globally, the advisory cautions that this number does not necessarily indicate the actual number of affected systems, as many factors can influence exposure status.

The advisory recommends several practical mitigation steps, including removing direct internet exposure of RDP, enforcing account lockout policies, segmenting networks to limit lateral movement, and maintaining offline, immutable backups that are stored separately from the active network. Additionally, periodic external queries using tools like ZoomEye can help identify forgotten or unmonitored remote-access services, providing a more accurate representation of an organisation's exposure risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Beyond PR Counts: How Hacktoberfest 2026's Quality-First Pivot Is Reshaping Open Source Development Habits

Originally published on tamiz.pro . For nearly a decade, Hacktoberfest operated on a simple, gamified metric: submit four pull requests to qualifying repositories in October, earn a t-shirt.

  • Hacktoberfest 2026 pivots to prioritize high-quality contributions over quantity.
  • Old model led to 35% of PRs being closed for low quality, overwhelming maintainers.
  • New framework evaluates contributions based on review depth, code complexity, and impact.

Handling Legal Document Metadata and File Integrity in Cross-Border Civil Registration Workflows

If you've ever built a system that touches legal or civil documents (court filings, immigration paperwork, civil registry integrations), you've probably run into a problem that has nothing to do with…

  • Manage legal document metadata and file integrity in cross-border civil registration workflows.
  • Hash every document version and store metadata about transformations for an auditable trail.
  • Automate authority lookup using cached Hague Convention membership list to eliminate errors.

More from Saturday 3 October →