VUNVAULT Newsroom

Every breach. Every bulletin. One feed.

Breaking cybersecurity news, threat intelligence and advisory coverage — from Kenya's digital frontier to the world's biggest incidents.

27 stories live 11 local & African 16 global Updated Aug 2026
● NEW Kenya names Martin Koyabe inaugural NCSA chair ● NEW PaperCut NG/MF zero-day exploited; emergency patches out ● NEW CISA KEV: Citrix NetScaler CVE-2026-8452 is RCE ● NEW Next.js patches two unauthenticated RCEs ● BREAKING DeepSeek hijacked via Telegram agent for autonomous attacks ● KENYA SIM-swap fraud: Ksh 500M stolen, attacks up 67% ● ADVISORY CISA flags actively exploited N-able N-central flaw ● ZERO-DAY Metabase CVSS 10 SQLi hits Framework, Tally, n8n ● BREACH ShinyHunters publishes 1.6M RingCentral records ● KENYA Interpol ranks Kenya 2nd-most vulnerable in Africa ● NIGERIA NCC orders telecoms to fund cybersecurity ● CISCO Firewall flaws on CISA KEV ● BREAKING DeepSeek hijacked via Telegram agent for autonomous attacks ● KENYA SIM-swap fraud: Ksh 500M stolen, attacks up 67% ● ADVISORY CISA flags actively exploited N-able N-central flaw ● ZERO-DAY Metabase CVSS 10 SQLi hits Framework, Tally, n8n ● BREACH ShinyHunters publishes 1.6M RingCentral records ● KENYA Interpol ranks Kenya 2nd-most vulnerable in Africa ● NIGERIA NCC orders telecoms to fund cybersecurity ● CISCO Firewall flaws on CISA KEV

Local & African News

Coverage from Kenya and across the continent.

Global News

The incidents shaping security worldwide — and what they mean for you.

Journalists & partners — work with VUNVAULT

Expert commentary, threat intelligence and data for your reporting. Reach the press office at [email protected].

Visit Press & Media →
← Back to the newsroom
Kenya · Local

Kenya Appoints Martin Koyabe as Inaugural Chair of the National Cybersecurity Agency

ICT Principal Secretary John Tanui announced Dr Martin Koyabe as non-executive chair of NCSA’s first board, as Kenya pushes the digital economy toward 30% of GDP.

VUNVAULT News Desk · 24 Aug 2026 · 6 min read · sourced reporting
Dr Martin Koyabe, appointed non-executive chair of Kenya’s National Cybersecurity Agency. Photo: Martin Koyabe / X, via Eastleigh Voice.

Kenya has named the first chair of a dedicated national cyber agency. On 24 August 2026, ICT and Digital Economy Principal Secretary Eng. John Tanui announced that Dr Martin Koyabe, a UK-based cybersecurity expert, is the inaugural non-executive chairperson of the board of the National Cybersecurity Agency (NCSA).

Tanui said the appointment lands as Kenya tries to grow the digital economy toward 30 percent of GDP. A standalone agency, he argued, is a strategic milestone: government services, payments, AI, cloud, data centres, BPO and “digital jobs” now sit on infrastructure that is also a national-security problem. The digital economy is no longer a side bet for Nairobi. It is the growth story the government sells to investors, and it is the attack surface criminals and geopolitically motivated actors already use.

That is why a chairperson’s name, announced on a Monday in late August, is more than a personnel notice. It is the first time the Kenyan state has put a single public face on a problem that has spent 2026 leaking into headlines — Interpol rankings, SIM-swap factories, a defaced presidency website, and billions of logged threat events in a single Communications Authority quarter.

Why a new agency, and why now

Kenya has spent 2026 in Interpol’s headlights. The African Cyberthreat Assessment Report 2026 placed the country second on the continent for exploitable digital vulnerabilities detected in 2025, at 11.9 percent, behind only South Africa. SIM-swap investigations jumped 327 percent. More than 123,000 fraudulent SIMs were issued. About Ksh 500 million left mobile wallets. In July, president.go.ke was defaced with a bitcoin ransom note. The Communications Authority has previously reported 2.35 billion cyber-threat events in a single quarter. None of that is a staffing gap in one ministry. It is a systems failure across telcos, banks, counties and the centre of government.

Until NCSA, cyber policy in Kenya lived in overlapping rooms: the Ministry of ICT, the Communications Authority, the National KE-CIRT/CC, the Directorate of Criminal Investigations’ cybercrime unit, and a patchwork of bank and telco SOCs that do not share a same-day freeze protocol. When a SIM is hijacked, the bank can often see the theft in real time and still cannot kill the line without a court order. When a government portal is probed, the ticket may sit in a queue that was never designed for nation-state tempo. A board that outlasts a single circular is supposed to close that gap.

Koyabe’s brief, as Tanui framed it, is to help build an institution that can protect digital infrastructure without smothering the innovation story Nairobi sells. That tension is the job. Enough control to stop a SIM-swap factory. Not so much that every startup waits six months for a clearance. Kenya wants data-centre investment, AI talent and BPO contracts. Those buyers now ask, before they ask about tax, who is accountable when the VPN is last year’s build.

Who Martin Koyabe is — and what a non-executive chair can actually do

Koyabe is a UK-based practitioner, not a career politician. Coverage in TechAfrica News and Eastleigh Voice presents him as a cybersecurity expert appointed to a non-executive chair, which in Kenyan public bodies usually means he does not run day-to-day operations. He chairs the board. He sets tone, hires or recommends a chief executive, and is the person Parliament and the press will call when the next defacement happens. That is useful. It is also limited. A chair is not a security operations centre. A chair cannot patch a county hospital’s Fortinet box from London.

What a serious chair can do in the first 100 days is narrower and more important: lock a mandate, a budget line, and a legal channel into telcos and banks. Interpol’s Kenya chapter is not a mystery novel. The holes it names are unpatched routers, weak VPNs, misconfigured document portals, and SIM-swap social engineering of shop-floor agents. Those are operator problems. NCSA only matters if operators must answer it.

Watch three documents. First, the legal instrument that says who NCSA can compel — critical-infrastructure operators, licensees, counties. Second, the budget. An agency without analysts, incident responders and a 24-hour desk is a letterhead. Third, the interface with KE-CIRT, CA and DCI. If those three still run parallel war rooms, Kenya has added a fourth logo, not a command structure.

The economic argument Tanui is making

The 30 percent of GDP figure is a political target, not a SOC metric, but it explains the timing. eCitizen, Huduma, M-Pesa, the digital superhighway, Konza, and the push for AI and cloud jobs all assume the network is trustworthy enough for a teacher in Voi to pay school fees on a phone. Interpol’s ranking is the opposite of that assumption. Foreign partners — the UK review of 20 August is the nearest example — will not keep writing training cheques into a vacuum. They want a counterpart. NCSA is that counterpart, or it is nothing.

There is also a private-sector test. SACCOs hold on the order of a trillion shillings. Hospitals run imaging and billing on the same class of VPN appliances Gunra affiliates scan. Print estates in universities still expose PaperCut. Banks still treat SIM-swap as a customer-negligence story even after the High Court, in June 2026, held Safaricom and Diamond Trust Bank jointly liable for a Ksh 4.4 million loss. A national agency that cannot change those incentives will be ignored by the people who actually run the pipes.

What to watch between now and the next crisis

The next crisis will not wait for a board induction. PaperCut’s August zero-day, Citrix NetScaler in CISA’s KEV catalogue, and Check Point’s July ransomware spike are all live. Kenyan organisations are already in those datasets even when they are not named on the first slide. NCSA’s early usefulness is therefore boring: a public patch-priority list for operators, a same-day SIM-freeze protocol with CA and the banks, and a single number that a county CIO can call at 2 a.m.

A chair is not a SOC. The test is whether NCSA gets a budget, a mandate over critical operators, and a same-day channel with telcos and banks — the exact gaps Interpol named. Until then this is a nameplate. The appointment is still the most important Kenyan cyber story of late August, because it is the first time the state has put a single public face on the problem. The country will judge Koyabe not on the press release, but on whether the next SIM-swap ring, the next defacement, and the next ransomware note hit a desk that can act.

A 100-day checklist Kenya can hold him to

Public appointments die in the gap between the photograph and the first budget vote. A useful way to read the next three months is as a checklist, not a personality story. Day 30: a named chief executive or a dated search, and a one-page public mandate that says which operators NCSA can compel. Day 60: a written protocol with Safaricom, Airtel, the banks and KE-CIRT for same-day SIM freezes — the gap the High Court has already started to price. Day 90: a published patch-priority list for Kenyan critical operators that maps CISA’s KEV and Interpol’s boring holes (VPN, router, document portal) onto local estates. Day 100: a 24-hour desk that a county CIO can actually ring.

None of that requires Koyabe to write exploits. It requires the board to spend political capital on unglamorous plumbing. If those artefacts do not exist by year-end, Kenya will still have a chair, and Interpol will still have a ranking. Readers should keep both on the same desk.

The digital-economy target of 30 percent of GDP will be quoted again at the next conference. Quote it back with a question: what share of eCitizen, SACCO and hospital systems had an internet-facing admin plane last week, and who had the authority to order it shut. That is the chair’s real job description, whether or not it appeared in the 24 August announcement.

← Back to the newsroom
← Back to the newsroom
Kenya · Partnership

Kenya and the UK Review Cyber Partnership as Nairobi Seeks Stronger Digital Resilience

PS John Tanui and Deputy British High Commissioner Dr Ed Barnett met in Nairobi to review UK–Kenya cyber cooperation, standards and secure-by-design for emerging tech.

VUNVAULT News Desk · 20 Aug 2026 · 6 min read · sourced reporting
Kenyan officials and a British High Commission delegation meet in Nairobi. Photo via ICT PS John Tanui / ITWeb Africa.

Kenya and the United Kingdom sat down in Nairobi this month to review a cyber partnership that is supposed to turn policy paper into capacity. ICT Principal Secretary Eng. John Tanui and Broadcasting PS Steve Isaboke met Deputy British High Commissioner Dr Ed Barnett and FCDO officials on 20 August 2026.

The agenda was practical rather than ceremonial: progress on UK–Kenya Cyber Partnerships, how Kenya writes and implements cyber policy, and how to align local standards with global practice — including secure-by-design for emerging technology. Photos from the meeting, circulated via PS Tanui and picked up by ITWeb Africa, TechAfrica News and Tech Review Africa, show a working session, not a ribbon-cutting. That is the right visual. The wrong outcome is another memorandum that dies in a shared drive.

Four days later Kenya named Dr Martin Koyabe inaugural chair of the National Cybersecurity Agency. Read together, the two stories are one: Nairobi is trying to build a counterpart that London, and every other partner, can actually call. Partnerships fail when they have no address.

What “partnership” has to mean in 2026

Tanui has said cyber is no longer optional as government services, businesses and citizens move online. That sentence used to be a conference cliché. In 2026 it is a description of the threat board. Interpol ranks Kenya second in Africa for exploitable vulnerabilities. SIM-swap investigations are up 327 percent. The presidency website was defaced in July. Check Point’s July snapshot put African organisations at 3,237 attacks a week, above the global mean. The UK does not need to be told Kenya has a problem. Kenya does not need another workshop on why MFA matters. Both sides know the list. The meeting was about whether the list becomes muscle.

The UK side brings training, standards language, and a diplomatic channel into Five Eyes-adjacent practice without pretending Kenya is joining that club. It also brings hard-won scar tissue: National Cyber Security Centre advisories, the experience of ransomware against public services, and a regulatory culture that at least tries to make operators own their patch cycles. Kenya brings the live laboratory: M-Pesa, eCitizen, a mobile-money stack the size of a mid-European bank, SACCOs, counties, and a criminal market that already treats SIM-swap as a business process.

Skills, incident response and secure-by-design for AI and cloud were on the table. That is the right list. Secure-by-design is not a slogan for a slide. It means a new government portal does not ship with a default admin, a vendor VPN does not face the internet on day one, and an AI chatbot used by a ministry does not get fed ID numbers because nobody wrote a policy. The UK has paper on this. Kenya has production systems that will ignore paper unless a regulator, or NCSA, can say no.

Standards, not souvenirs

Aligning “local standards with global practice” is where these meetings usually go to die. ISO 27001 certificates appear. Nothing changes on the Fortinet in the county. The useful version of alignment is narrower. Publish a short list of controls that Kenyan critical operators must meet this year: MFA on all remote access, no default VPN credentials, immutable backups off the domain, a 72-hour patch window for CISA KEV items that match the local estate, and identity proofing before a SIM is moved. Then audit. Partners can fund the audit. They cannot pretend the certificate is the control.

Incident response is the second place paper fails. A joint partnership that does not produce a playbook a SACCO can run at night is theatre. The playbook has to say who freezes a line, who talks to the public, who images a box, and who calls KE-CIRT. It has to work when the person who attended the UK course is on leave. That is why tabletop exercises — not more MOUs — are the metric. If, by the next review, Kenyan CERTs, NCSA and a sample of banks and telcos have run a joint exercise with a written after-action, the partnership is real. If the deliverable is another photograph, it is not.

The local test: SACCOs, counties, telcos

State House will get help. The question is whether a SACCO in Nyeri, a county hospital in Taita Taveta, and a telco agent in Eastleigh get any of it. Gunra’s CISA advisory is about Fortinet holes and stolen VPN sessions — the same class of kit African hospitals and SACCOs actually run. PaperCut’s August zero-day hits print servers in universities. Citrix NetScaler is still on public VIPs at banks and ISPs. A UK partnership that trains 40 people in Nairobi and never touches those boxes has not reduced risk. It has produced alumni.

SIM-swap is the uniquely Kenyan test. Attackers socially engineer a shop-floor agent, take the number, intercept OTPs, empty the wallet. Banks see it. Telcos argue process. Courts are starting to assign liability — Safaricom and Diamond Trust Bank were held jointly liable in June 2026 for a Ksh 4.4 million loss. A serious partnership would treat identity-before-SIM-move as a standards item, not a customer-education poster. If FCDO-funded work does not change how a line is frozen on the same day, it has missed the cash machine criminals actually use.

What to watch next

Watch for three public artefacts. One: a published, dated list of joint activities — exercises, secondments, a standards note — not a communiqué. Two: whether NCSA, not only the ministry, is the named counterpart. Three: whether county and SACCO systems, not only the centre, are in scope. Digital trust is the product both governments say they want. Resilience is how you measure it. The 20 August meeting was a review. Reviews only matter if the next one has numbers.

If the partnership works, Kenyan CERTs, NCSA and operators will have playbooks, not just photos of a boardroom. That is a six-month test, not a news-cycle test. VUNVAULT will treat the next joint exercise, the next published control list, and the next SIM-freeze protocol as the story. The handshake was 20 August. The work is everything after.

Money, secondments, and the risk of training tourism

UK–Africa cyber programmes have a known failure mode: tickets, hotels, and a cohort of well-trained people who return to an unchanged VPN. Secondments in the other direction — a Kenyan analyst sitting in a UK SOC, a UK incident responder sitting in KE-CIRT for a month — cost more politically and work better. If the FCDO line item is only workshops in Nairobi, ask why. Skills matter. Skills without authority over telco identity proofing do not stop a 327 percent SIM-swap surge.

Secure-by-design for emerging tech is the part of the agenda that will attract the most slogans. Make it concrete. Any new government AI or cloud project that cannot show: no default credentials, no public management plane, a data-handling rule for prompts, and a named owner for patching, should not go live. The UK can help write that gate. Kenya has to enforce it. NCSA, four days after this meeting, is the agency that should own the gate. If the partnership reviews skip NCSA and stay in the ministry, the institutional story is already splitting.

Keep the 20 August date next to Check Point’s July numbers and PaperCut’s 28 August emergency builds. Partnerships that cannot absorb a week like that are news. Partnerships that issue a joint note on those CVEs, in Kenyan operator language, within a fortnight, are infrastructure. Demand the latter.

← Back to the newsroom
← Back to the newsroom
Africa · Threat intel

Africa Hit With 3,237 Cyberattacks a Week as July Ransomware Breaks the 2026 Pattern

Check Point Research: African organisations averaged 3,237 weekly attacks in July. Nigeria 4,975, Angola 5,714. Global ransomware victims jumped 49% month-on-month to 964.

VUNVAULT News Desk · 17 Aug 2026 · 6 min read · sourced reporting
GenAI-risk imagery used in African coverage of Check Point’s July 2026 threat report. Source: IntelligentCIO Africa / related Check Point reporting.

Check Point Research’s July 2026 snapshot is ugly for Africa. Organisations on the continent averaged 3,237 cyberattacks per week — above the global mean of 2,336 (up 3% month-on-month and 16% year-on-year). Latin America led at 3,561; APAC sat at 3,316. Inside Africa, Angola was hardest hit at 5,714 weekly attacks per organisation, then Nigeria at 4,975. Kenya was also named in the regional list.

Those are not abstract “threats.” They are weekly averages per organisation: the number of times a firewall, mail gateway or endpoint stack is hit hard enough to count. A Kenyan bank, a Nigerian telco and an Angolan energy operator are not seeing the same internet everyone else sees, plus a little extra. They are sitting above the global mean, in some cases more than double it, while their SOC headcount and patch windows are not.

Lorna Hardie, Check Point’s Africa regional director, said risk is stacking on several fronts at once: volume, ransomware and GenAI exposure in daily work. That triad matters because each one used to be a separate budget conversation. In July they arrived in the same report, in the same month ransomware broke its 2026 pattern.

Ransomware broke the first-half pattern

Globally, reported ransomware victims hit 964 in July — up 49% from June and 87% versus July 2025. The first half of 2026 had averaged about 672 a month. July was not a noisy week. It was a regime change in the numbers. Business services took 32.5% of victims, industrial manufacturing 14.4%, consumer goods 13.4%. The United States still led country counts at 39.4%. The Gentlemen and Qilin each had 14% of published attacks; DeadLock had 10% and 97 victims.

Leak-site counts are a lagging, incomplete measure — they only capture crews who publish — but a 49% month-on-month jump is too large to hand-wave as better reporting. Something in the affiliate economy got easier: initial access via VPN and firewall bugs, stolen credentials, or simply more buyers for access. CISA’s Gunra advisory, out on 10 August, is one named example of that economy: leaked Conti code, an 80% affiliate cut, Fortinet holes, double extortion. Check Point’s July spike is the statistical weather. Gunra is one of the storms.

On the continent, financial services, government and energy/utilities remained the three most attacked industries. That mapping should surprise nobody who has watched African incident response. Banks hold the wallets. Government holds identity and tax. Energy holds the lights. Crews go where payment is reliable and downtime hurts enough to negotiate. A SACCO, a national power utility and a ministry ERP are different organisations with the same week on the calendar.

Email is still the door — Africa more than anywhere

Africa had the world’s highest phishing rate in the July set: one in every 106 emails. That is not a user-awareness problem first. It is a gateway, DMARC, and identity problem. When one in a hundred messages is hostile, training videos do not outrun the inbox. MFA on mail, phishing-resistant authentication where the crown jewels sit, and a culture of not using SMS OTPs as the second factor — especially in a SIM-swap market — are the controls that move the number.

Kenya’s Interpol chapter makes the same point from a different dataset. SIM-swap is phishing’s cousin: social engineering of a human (the telco agent) instead of a mailbox, then OTP interception. Check Point counts the mail. Interpol counts the SIMs. Criminals use both. A SOC that only watches one is watching half the cash machine.

GenAI is now a leak path, not a future risk

One in 36 enterprise GenAI prompts carried a high risk of leaking sensitive data. Eighty-eight percent of organisations that regularly use GenAI saw high-risk prompt activity. Personal data showed up in 70% of those organisations. Staff are pasting customer records, source, and ID numbers into tools that were not in last year’s data map. The model is not “hacking” the company. The company is handing the model the data.

For African enterprises this is worse than the average because so much of the economy is identity-plus-payments: mobile numbers as account numbers, national IDs as KYC, WhatsApp as the helpdesk. A prompt that looks like “summarise this customer complaint” can be a dump of PII into a vendor cloud the DPO never approved. Hardie’s warning is not that AI will become a weapon. It is that ungoverned AI already is a data-loss channel, every working day.

A usable policy is short. Name the tools that are allowed. Block the rest at the proxy. Ban pasting ID numbers, card data, source code and health records. Log prompts where the law requires. Train once, then enforce. Ninety-page AI strategies do not survive a sales team with a free ChatGPT tab.

What Kenyan and Nigerian SOCs should do with July

Do not wait for a localised annex. The global ransomware jump is the reason to test backups this week, not next quarter. Offline, immutable copies, on a network the domain admin cannot reach, restored at least once in anger. MFA on every remote path. A 72-hour rule for KEV-listed VPN and firewall bugs — Citrix CVE-2026-8452 and PaperCut’s August zero-day are the current exhibits. A written rule for GenAI. An email path that does not treat SMS as a second factor for high-value transactions.

For Kenyan and Nigerian SOCs the message is not new, just louder: ransomware is accelerating, email is still the door, and ungoverned AI tools are now a daily leak path. Prevention-first controls — MFA, allow-lists, offline backups, and a rule for which AI tools staff may use — are the floor. Check Point’s July numbers are a scoreboard. The play is still the same. Run it.

How to read a vendor index without drowning

Check Point sells prevention. Treat the index as a weather report from a company that makes umbrellas, then still use the numbers that other datasets rhyme with. Interpol’s Kenya chapter, CISA’s Gunra advisory, and the 49% ransomware jump do not need Check Point to be true. They need Check Point to be directionally right, which July was. When three unrelated sources say volume, ransomware and identity fraud are up, a SOC that waits for a fourth is collecting stamps.

Translate the Africa averages into tickets. 3,237 weekly attacks per organisation is not 3,237 incidents. It is 3,237 reasons your allow-list and your MFA either hold or they do not. Angola at 5,714 and Nigeria at 4,975 are a reminder that “Africa” is not one risk. Operators in Lagos and Luanda need more than a continental average. They need the industry cut: finance, government, energy. If you run one of those three, you are not in the mean. You are in the column.

Set a July-driven drill: restore from offline backup, revoke a suspected VPN session, and block an unapproved GenAI domain, all in one afternoon. Time it. If any step needs a vendor or a change board, that step is your real vulnerability. The report will be published again next month. Your restore time will not improve unless you measure it.

One more translation for executives who will only read the ransomware line: 964 published victims in July is not “almost a thousand companies got encrypted.” It is almost a thousand that were named on leak sites. The quiet victims — the ones who paid early, the ones who never made the blog — are not in the 964. Budget as if the real number is higher. Then look at your own sector’s share. Business services at 32.5% means professional firms are not spectators. If you are a Kenyan or Nigerian professional-services shop with a VPN and a file server, you are in the fat part of the chart, not the tail.

← Back to the newsroom
← Back to the newsroom
Kenya · Interpol

Interpol: Kenya Second in Africa for Exploitable Vulnerabilities as SIM-Swap Fraud Explodes

Kenya accounted for 11.9% of Africa’s detected exploitable holes in 2025. SIM-swap investigations jumped 327%, with 123,000 fraudulent SIMs and about Ksh 500 million drained from wallets.

VUNVAULT News Desk · 05 Aug 2026 · 6 min read · sourced reporting
Excerpt from INTERPOL’s African Cyberthreat Assessment Report 2026, as published by People Daily Digital.

Interpol’s African Cyberthreat Assessment Report 2026 puts Kenya second on the continent for exploitable digital vulnerabilities detected in 2025 — 11.9 percent, behind South Africa at 43.6 percent and ahead of Nigeria at 9.1 percent. Tanzania was seventh at 3 percent; Uganda 22nd at 0.5 percent.

Read that ranking slowly. It is not “Kenya is the second-most hacked country.” It is a share of detected exploitable holes — the unpatched routers, weak VPNs and misconfigured portals that scanners find before a human does. South Africa’s 43.6 percent is a function of connectivity and visibility as much as failure. Kenya’s 11.9 percent, on a smaller internet, is still a flashing light. Nigeria at 9.1 percent is the regional peer. East Africa’s spread — Tanzania 3 percent, Uganda 0.5 percent — shows how uneven detection still is. Absence of findings is not absence of risk.

People Daily, citing the same report, said Kenya recorded more than 46,786 DDoS-style attacks on telecoms in the first half of 2025 and hundreds of millions of intrusion attempts against government ICT between July and September 2025. Those are industrial volumes. They are also the kind of numbers that make a quarterly CA report and then vanish unless someone owns the patch cycle. The holes Interpol names are not exotic zero-days. They are last year’s firmware.

SIM-swap is the cash machine

SIM-swap investigations in Kenya surged 327 percent in 2025. More than 123,000 fraudulent SIMs were issued. About US$3.8 million (Ksh 491–500 million) was drained from mobile wallets, according to Nation, People Daily and tech-ish coverage of the Interpol figures. That is not a rounding error in a bank’s fraud budget. It is a parallel payments business running on social engineering of telco agents.

The method is now folk knowledge. An attacker knows your number, or buys it. They call or walk into a shop with a story and enough of your details to pass a weak check. The SIM is reissued. OTPs for M-Pesa, mail and banking land on the new card. The wallet empties in minutes. The bank’s fraud team can watch the velocity and still cannot freeze the line without a process that looks like a court. The customer is told they were negligent. Sometimes they were. Often the identity proofing at the counter was theatre.

In June 2026 the High Court held Safaricom and Diamond Trust Bank jointly liable for a Ksh 4.4 million SIM-swap loss. That judgment is more important than another awareness poster. It says the industry’s “customer clicked” defence has a limit. If NCSA and CA want a single reform that matches Interpol’s Kenya chapter, it is this: prove identity before a SIM moves, and give banks a same-day freeze that does not require a judge at midnight.

In July, president.go.ke was defaced with a 5-bitcoin ransom demand. That incident is a different class — website integrity, not wallet theft — but it sits in the same month as the Interpol conversation for a reason. The state’s public face and the citizen’s phone are both in play. A country that cannot keep the presidency site clean will not convince a SACCO member that the wallet is safe.

Government as a target, not a bystander

Hundreds of millions of intrusion attempts against government ICT in one quarter are what a noisy internet looks like when you finally measure it. Most will be commodity scans. Some will not. The exploitable share — the 11.9 percent — is the part that matters. Document portals left on default, VPNs on last year’s build, routers with management on the WAN. African governments have spent a decade putting services online. They have not spent a decade taking management planes off the public net. Interpol is describing that lag in a table.

This is why the 24 August NCSA chair appointment and the 20 August UK partnership review are not separate lifestyle stories. They are attempted institutional answers to a report that says Kenya has the holes, the SIM-swap market, and no regional net to stop crews hopping the border after a job.

AI and a missing regional net

Interpol says AI featured in 55 percent of reported African cybercrime. Deepfakes, synthetic identities and automated phishing are now normal. A voice that sounds like a director, a face on a video KYC, a thousand phishing mails generated in a minute — those are production techniques, not lab demos. The 55 percent figure will be argued over (what counts as “featured”), but the direction is not arguable. The cheap generation of believable lies arrived faster than bank and telco playbooks.

The agency’s other warning is institutional: there is no unified regional response, so crews hop borders. A SIM-swap ring can recruit in one capital, cash out in another, and host infrastructure in a third. National CERTs that do not share indicators at operational speed are playing chess one move behind. Legislation such as Kenya’s Computer Misuse and Cybercrimes (Amendment) Bill 2024 is necessary and not sufficient. You cannot prosecute your way out of unpatched routers.

What would actually move Kenya off second place

Patch the routers. Prove identity before a SIM moves. Give banks a same-day freeze. Take VPN and firewall management off the public internet. Treat CISA KEV items that match the local estate as 72-hour work. Run a joint exercise between KE-CIRT, telcos and two banks, then publish what broke. Those sentences are less glamorous than a ranking, and they are the ranking’s only useful sequel.

Interpol has told Kenya, in a table, where it stands. The next African Cyberthreat Assessment will not be kinder because a chair was named. It will be kinder if the holes shrink. That is a year of unglamorous work. It should have started before the report. It has to start now.

How a ranking gets misused — and how to use it anyway

Oppositions will weaponise 11.9 percent. Ministries will say detection is a compliment. Both miss the operational read. Interpol is counting holes scanners can see. More connectivity and more measurement raise your share. That does not make the holes imaginary. Kenya’s SIM-swap cash-out and the presidency defacement are not measurement artefacts. They are losses. Use the ranking as a prioritisation tool: South Africa-scale problems on a Kenya-scale SOC, with a mobile-money rail criminals already understand.

Share the report with boards in one page. Three numbers: 11.9 percent of Africa’s detected exploitable vulnerabilities; 327 percent SIM-swap investigations; about Ksh 500 million out of wallets. Three actions: identity before SIM move; same-day freeze; management planes off the internet. One owner per action. If a board leaves with only the ranking, the report has been wasted on prestige panic.

Regional cooperation is the part Kenya cannot do alone. Crews hop borders because indicators do not. A practical start is bilateral: Kenya–Tanzania and Kenya–Uganda sharing SIM-swap and VPN indicators in hours, not in annual workshops. Interpol’s complaint about a missing regional net is a dare. Take it. The 2027 assessment will otherwise print the same paragraph with a new year.

Keep the presidency defacement and the SIM-swap judgment in the same folder as the 11.9 percent. Rankings persuade ministers. Judgments persuade telcos. Defacements persuade the public. Interpol supplied the first. Kenyan courts and a bitcoin note on president.go.ke supplied the other two. Policy that only answers the ranking will miss the wallet. Policy that only answers the wallet will miss the routers. NCSA’s job, if it is real, is to answer both in the same week.

← Back to the newsroom
← Back to the newsroom
Global · Zero-day

PaperCut NG/MF Zero-Day Exploited in the Wild; Emergency Patches for All Supported Versions

PaperCut confirmed active attacks on every supported NG and MF build. A university DFIR team found it. Emergency patches shipped 28 August 02:10 AEST. CVEs 2026-81578 and 2026-82078.

VUNVAULT News Desk · 28 Aug 2026 · 6 min read · sourced reporting
PaperCut branding from coverage of prior and current print-server attacks. Source: Recorded Future / The Record-style reporting on PaperCut flaws.

PaperCut Software told customers on 27–28 August 2026 that attackers are exploiting a zero-day in PaperCut NG and PaperCut MF — every currently supported version. The company said it has confirmed customer incidents. Huntress reported limited exploitation in two customer environments, with basic post-exploitation commands to identify user and OS.

A university’s own forensics team caught the abuse and told the vendor. That detail should be taught in every DFIR course. The customer found it. The vendor reproduced it. Emergency, out-of-cycle builds shipped at 2:10 a.m. AEST on 28 August for v25 and v26 on Windows, Linux and macOS; v24 followed the same day. These are emergency builds, not a normal release train. If your change window is “Tuesdays,” you have already lost a weekend of scanner time.

PaperCut is print-management software. That sentence is why so many estates still leave it on the internet. It feels like a printer problem, not a domain-admin problem. In 2023, CVE-2023-27350 proved otherwise: Cl0p and LockBit used PaperCut as a beachhead. Schools, councils, hospitals and shared-services print rooms became ransomware stories. The 2026 zero-day is the sequel. Anyone who treated 2023 as a one-off is in the sample.

What the chain actually is

Rapid7 says the vendor later assigned CVE-2026-81578 (authentication bypass, CVSS 8.8) and CVE-2026-82078 (unsafe dynamic class loading in the database connector, CVSS 9.4). PaperCut’s Apache Tapestry “complex direct” requests can display one page and execute a component from another. Access checks applied only to the displayed page. Point the display at a public Error or Exception page, invoke ConfigEditor or UserList, rewrite user-lookup JDBC settings, get remote code execution.

You do not need to be a Tapestry expert to understand the operational point. A page that looks harmless was enough to reach a component that was not supposed to be public. The first emergency patch could be bypassed via the Home page; a later build closed that. If you applied only the first emergency build, you are not done. Read the vendor note. Apply the build that actually closed the Home-page path. Then keep the Application Server off the public internet so the next Tapestry footgun is not a global scanning event.

Huntress’s two customer cases showed basic post-exploitation: who am I, what OS is this. That is reconnaissance, not yet ransomware. Do not take comfort. The gap between whoami and a locker is a script. PaperCut’s 2023 history says the script will arrive, if it has not already in environments Huntress does not see.

What to do in the next hour

If the Application Server is on the internet, restrict it to trusted IPs now — even if you see nothing in the logs. Then patch. Hunt: suspicious activity from pc-app.exe; missing or truncated server.log; log lines “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST”. Absence of those lines does not mean you are clean. Attackers who know the log signatures will avoid them.

Assume compromise if the server was internet-facing between the first confirmed exploitation and your patch. Rotate credentials the print environment can touch. Check for new local admins, unexpected scheduled tasks, and outbound traffic to unknown hosts. PaperCut often runs as a privileged service on Windows. That is the point of the product from an attacker’s chair.

Then do the architecture you skipped in 2023. The Application Server should not have a public A record. Put it behind VPN or allow-listed management. Separate it from domain admin. Monitor it as a tier-0 adjacent asset, because for many schools it already is one: it talks to directories, it stores card IDs, it sits on the same VLAN as everyone who prints.

Why African estates are in the target set

PaperCut’s 2023 flaw was used by Cl0p and LockBit. This one will be scanned. Schools, councils and African print estates that left NG/MF on the public net should assume they are in the target set. Universities in Nairobi, Johannesburg and Lagos run the same print-accounting logic as a US campus. Shodan does not care about the country code. A public PaperCut login page is a public PaperCut login page.

If you outsource print, call the vendor today and ask which build they are on, whether the server is internet-facing, and whether they applied the Home-page follow-up. Get the answer in writing. If they stall, treat the contract as an incident.

The rest of the newsroom this week — Citrix in KEV, Next.js RCEs, Gunra on Fortinet — is the same lesson in different logos. Internet-facing admin planes get exploited. Emergency patches exist because someone already lost. PaperCut told customers at 2:10 a.m. because that is when the builds were ready. Your job is not to wait for a local CERT bulletin. Your job is to take the server off the internet and install the build. Then keep it off.

Print is identity infrastructure

Card IDs, follow-me printing, and directory sync mean PaperCut is closer to IAM than to a toner contract. Treat it that way in the asset register. If it can create or look up users, it is in the same conversation as VPN and SSO. The 9.4 CVSS on unsafe class loading is the technical proof. The 2023 ransomware wave is the historical proof. The university DFIR team that called the vendor is the cultural proof: someone has to own the box hard enough to notice.

For managed-service customers, write three questions into the ticket and do not close it without answers: build number after the Home-page fix; whether the Application Server still has a public DNS name; whether logs were intact across 27–28 August. If logs were rotated or truncated, you are in Huntress’s hunt category even if nobody has called you. Take a forensic image before you “clean up.”

Then schedule the unsexy follow-up: network allow-list, privileged-service review, and a tabletop that starts with “print accounting is down and pc-app.exe spawned cmd.” If that tabletop feels silly, you have not read 2023. PaperCut is how a lot of quiet organisations first met LockBit. The 2026 zero-day is how they meet whoever comes next, unless the server finally leaves the internet.

If you have no idea whether you run PaperCut, ask facilities and the helpdesk, not only IT. Print accounting is often bought by a department that never files a CVE ticket. The Application Server may be a VM named after a building. Find it by the login page, by the process name pc-app.exe, and by the vendor invoice. The emergency build at 02:10 AEST only helps hosts you know you have. Unknown hosts will be the ones in the next Huntress note.

← Back to the newsroom
← Back to the newsroom
Global · CISA KEV

CISA Adds Citrix NetScaler CVE-2026-8452 to KEV After June ‘DoS’ Patch Turns Into RCE

Federal deadline 29 August. Attackers are dropping x.php and z.php webshells. Thirty-six exploitation attempts from 12 countries were counted in 12 days.

VUNVAULT News Desk · 27 Aug 2026 · 6 min read · sourced reporting
CISA / Citrix NetScaler CVE-2026-8452 graphic from exploit reporting (TeamWin / related KEV coverage).

On 26 August 2026 CISA added six bugs to the Known Exploited Vulnerabilities catalog. The one that should empty change-windows is CVE-2026-8452 in Citrix NetScaler ADC and Gateway — a memory-bounds issue Citrix patched on 30 June as denial-of-service. Researchers and CISA now treat it as unauthenticated remote code execution. Federal civilian agencies had until 29 August to fix it.

That sentence should make every NetScaler owner sit down. In June it was a DoS. In August it is RCE, in KEV, with a three-day federal clock. The box did not change personality. The analysis did. Anyone who triaged the June advisory as “we can ride out a reboot” now has a webshell problem. This is the CitrixBleed pattern: a VPN and ADC appliance on the public internet, a first advisory that understates impact, and a second week when everyone else is already inside.

Previdian (formerly KEVIntel) said attackers dropped webshells named x.php and z.php and ran discovery commands such as id and echo. Telemetry: 36 exploitation attempts in 12 days from 12 unique IPs in Switzerland, Germany, Hong Kong, Japan, the Netherlands, Russia, Singapore, Türkiye, the United States and Vietnam. That is not a single crew in one neighbourhood. That is a global scan with enough success to bother dropping PHP.

What KEV actually means, and why 29 August was not a suggestion

CISA’s Known Exploited Vulnerabilities catalogue is a compliance instrument for US federal civilian agencies (BOD 22-01) and a practical priority list for everyone else. “Due 29 August” means if you are FCEB, you patch or you explain. If you are a bank in Nairobi or an ISP in Lagos, nobody will fine you for missing that date. The scanners will not wait for your regulator either. KEV is the closest thing the industry has to a shared “do this now” list. When Citrix ADC is on it, you assume your public VIP is being touched.

Unauthenticated RCE on a gateway is as bad as it sounds. NetScaler ADC and Gateway terminate SSL, broker VPN, and often sit in front of everything that matters. A webshell on that box is not “a web server got popped.” It is a chance to steal sessions, rewrite traffic, and pivot into the directory. Hunt x.php and z.php, but do not stop there. Names are cheap. Look for unexpected PHP, unexpected processes, and configuration changes after 30 June — especially if you delayed the June build because it was “only DoS.”

The rest of the 26 August list

CISA also listed older bugs Cisco Talos tied to Chinese cybercrime set UAT-10147 against Windows and Linux web servers in education, media, tech and gaming — including CVE-2022-0995, CVE-2015-5287, CVE-2015-3246 and CVE-2021-23758 (due 9 September) — plus Microsoft SQL Server CVE-2019-1068 (due 29 August with the NetScaler bug).

Those dates tell a second story. 2015 and 2019 bugs are still being exploited in 2026. UAT-10147 does not need a new zero-day if your web stack is a museum. Education and media are named because they patch slowly and still run internet-facing apps. If your estate has an old SQL Server or an unpatched Linux box from a forgotten faculty project, you are in the same set. The NetScaler item is the fire. The old bugs are the reminder that last decade’s homework is still due.

The CitrixBleed lesson, again

Do not trust a vendor’s first severity if the box sits on the internet. Memory-safety issues in SSL terminators have a habit of growing up into session-theft and RCE once researchers and attackers have a month with the patch. If you run ADC or Gateway, confirm you are on the June 30+ builds — and whatever Citrix shipped after the RCE restatement. Hunt those PHP names. Take the management plane off the public net. Management on a public VIP is how a three-day KEV window becomes a three-year incident.

Session replay and cookie theft were the scars of prior Citrix episodes. Even if CVE-2026-8452 is “only” RCE plus a webshell in the public write-ups, treat sessions as burned if the appliance was vulnerable and public. Rotate. Force re-auth. Check VPN logs for odd geographies that match the twelve-country list, knowing that list is a floor, not a ceiling.

African banks and ISPs

African banks and ISPs that still advertise NetScaler on a public VIP are in the same scanner’s path as everyone else. There is no African exemption in mass exploitation. If your SSL VPN is the front door for a thousand staff on hybrid work, this is a business continuity event, not an IT ticket. Schedule the outage. Patch. Hunt. Inform whoever owns cyber insurance before they hear it from a leak site.

Pair this with the rest of the week: PaperCut on print, Next.js on the website, Gunra on Fortinet. The common design error is an admin plane on the internet. Remove that error wherever you still have it. CISA gave federal agencies three days because the exploitation was already real. You can give yourself tonight.

How to hunt a gateway that was “only DoS” for two months

Start with inventory, not with hope. Every NetScaler ADC and Gateway, including the “temporary” one a vendor left in 2024. Version as of 30 June and as of today. Internet-facing or not. Then logs: new files under web roots, PHP names beyond x.php and z.php, configuration saves after mid-June, authentication anomalies from the twelve-country set plus your usual oddities. If you have packet capture on the VIP, keep it. If you do not, this is why you will buy it after the next one.

Assume session theft even when the public write-up stresses RCE. Gateways store the keys to other kingdoms. Rotate VPN credentials, revoke sessions, and force users through a clean build before they resume hybrid work. Tell helpdesks the story in one sentence so they do not reset people onto a still-compromised concentrator.

Document the June triage. If someone marked CVE-2026-8452 as low because Citrix said DoS, that decision needs a post-mortem, not a scapegoat. The process failed. Fix the process: internet-facing SSL terminators never sit on “wait for confirmation.” They sit on “patch when the vendor ships, hunt when KEV lists, rotate when RCE is confirmed.” That sentence should already be in your standard. If it is not, write it before the next CitrixBleed-shaped week.

If a partner terminates your SSL, they still have to patch. Put the KEV due date in the contract ticket. Ask for the build string, not a verbal “we are fine.” Gateway RCE is not a fine they can eat. It is your sessions. Get the string, get the hunt results for x.php and z.php, and get a written statement that management is not on a public VIP. File it. The 29 August federal clock is already a useful private-sector deadline even if no Kenyan statute says so.

← Back to the newsroom
← Back to the newsroom
Global · Framework

Next.js Patches Two Critical Unauthenticated RCEs: AVIF Image API and Windows Path Traversal

Vercel brought the August 2026 security release forward. Patch to 15.5.24 or 16.3.3. The AVIF bug is in libheif/sharp. CVE-2026-75604 (CVSS 9.0) hits Windows hosts using both routers.

VUNVAULT News Desk · 25 Aug 2026 · 6 min read · sourced reporting
Developer workstation used to illustrate the Next.js August 2026 security release. Patch notes: nextjs.org/blog/august-2026-security-release.

The Next.js team moved its August 2026 security release forward after finding a second critical bug in an upstream dependency. Fixes are in v16.3.3 (Active LTS) and v15.5.24 (Maintenance LTS), posted 25 August by Josh Story, Karim Rahal and Sebastian Silbermann.

Bringing a security release forward is a tell. The first bug was bad enough. The second, in an upstream library the image pipeline trusts, made waiting for the original date irresponsible. Next.js is not a niche framework. It sees tens of millions of weekly downloads. A large fraction of the public web — including African fintech, media and government-adjacent sites — ships on it. Unauthenticated RCE in that population is a mass event, even when the host is “just a marketing site” that happens to hold session cookies and an admin API.

The official note lives at nextjs.org/blog/august-2026-security-release. Read it. Then bump. This article is the operational translation for teams that will otherwise wait for Monday.

Two unauthenticated RCEs

Image Optimization / AVIF (critical). GHSA-2xp9-vwfh-vxw4 / GHSA-g89c-p67h-r497. A bug in libheif as used by sharp can execute code when Next.js optimises an attacker-controlled AVIF. Patched releases disable AVIF optimisation until upstream is fixed. Affects roughly 10.0.0 through 15.5.23 and 16.0 through 16.3.2. The attack is ugly because it rides a feature people turn on for performance: the framework fetches or accepts an image and re-encodes it. If that image is an AVIF chosen by an attacker — a user upload, a hotlinked CMS field, a newsletter thumbnail — the decoder is the exploit. You did not write a file-upload vulnerability. You inherited one from the image stack.

Disabling AVIF optimisation is a brake, not a philosophy. It means the maintainers would rather serve slower images than run attacker code. If your CDN or sharp pipeline still decodes AVIF outside Next.js, you have a second copy of the problem. Hunt other libheif consumers. This class of bug — parser RCE in media libraries — is old. It keeps working because every generation of web apps re-enables “helpful” transcoding.

Windows path traversal (critical, CVSS 9.0). CVE-2026-75604 / GHSA-p293-qw3h-jr36. Apps using both the Pages Router and App Router without Cache Components, on a Windows filesystem, can be hit unauthenticated. Linux and macOS are not affected. No workaround. Range: ≥13.4.0 <15.5.24 and ≥16.0.0 <16.3.3. Path traversal on Windows is a classic: backslashes, drive letters, and “safe” joins that are not. Dual-router apps are common in teams that migrated incrementally. The CVSS 9.0 and “no workaround” language means you patch or you are done. You cannot config-flag your way out.

Who must move, and who got a partial pass

Most production apps outside Vercel are self-hosted and must patch themselves. That is the majority of African deployments: a VPS, a Kubernetes cluster, an on-prem Windows box in a bank, a Docker image nobody has rebuilt since March. Vercel-hosted and Netlify-hosted sites were described as not running the affected image path (Netlify rewrites /_next/image to its own CDN) and not on Windows for the path-traversal bug. Vendors still told customers to upgrade. Take the upgrade. Partial passes expire when the next dependency slips.

If you are on Vercel or Netlify, you are not immune to the rest of your supply chain. A preview environment on a Windows runner, a self-hosted staging box, an old “we will migrate next quarter” app — those still count. Inventory every Next.js app, including the forgotten one. npm ls next is the start, not the finish.

What to type, then what to hunt

African startups on a Windows VM or a cheap VPS running Image Optimization against user uploads should treat this as production RCE until the bump is deployed. npm install [email protected] or [email protected], then redeploy. Do not wait for Monday. If you cannot bump today, turn off Image Optimization and take user-upload paths offline until you can. That is a worse user experience and a better night.

After the bump, hunt. Unexpected child processes from the Node service. Outbound connections from the app host that you did not write. New files under the Next cache directories. AVIF uploads around the time the advisory landed. On Windows dual-router apps, treat unauthenticated access logs as hostile until proven otherwise. Rotate secrets the app can reach: session keys, database URLs, cloud tokens in env files. RCE on the web process is RCE on everything that process can see.

This is a supply-chain story as much as a framework story

libheif via sharp via Next.js is the modern web: you did not choose the decoder, the decoder arrived with the image plugin. The same pattern sits under every “we just use the framework defaults” estate. Budget time for security releases the way you budget uptime. Subscribe to the Next.js security blog. Pin versions on purpose, and have a 24-hour path to unpin them when CVSS is 9.0.

The August 2026 release was moved forward because two critical, unauthenticated RCEs is one more than a responsible project can sit on. Your release train should move with it. Then look at the rest of the stack — PaperCut, NetScaler, Fortinet — and ask how many other “defaults” you still expose. The framework team did their job on 25 August. The remaining work is yours.

Inventory the apps you forgot

The dangerous Next.js app is not the one the platform team watches. It is last year’s campaign site, the HR portal on a Windows VM, the student project that grew a production database, the white-label instance a vendor hosts on a version they have not named. Make a list from DNS, from GitHub, from invoices. For each: version, host OS, Image Optimization on or off, Pages plus App router or not. The advisory’s affected ranges are specific. Your CMDB is not. Close that gap in a day, not a quarter.

If you cannot bump because of a breaking change, you still cannot stay. Isolate the app, disable the image route, or take it offline. A dark site is better than an unauthenticated RCE with your cloud keys in the environment file. Teams that “cannot deploy on Friday” should keep a security exception path. 25 August was a Tuesday. The next one will be a Friday. Build the path now.

Tell product managers why AVIF disappeared after the bump: the maintainers chose safety. Do not re-enable a custom sharp pipeline to get the pretty format back until libheif is actually fixed. That is how you buy a second incident with the first still open. Pin, patch, then wait for upstream. The blog post is dated 25 August. Your production version should be too.

For agencies and banks that wrap Next.js in a change-advisory board, attach the CVSS 9.0 and “no workaround” lines to the emergency change. This is not a feature release. It is the same class of motion as a VPN patch. If the CAB cannot meet, the security exception path is the CAB. Record who approved the bump. Record the old version. Then bump. The blog authors already did the hard part on 25 August.

← Back to the newsroom
← Back to the newsroom
Global · Ransomware

FBI, CISA and Allies Issue Joint Advisory on Gunra Ransomware

AA26-222A: Gunra uses Fortinet VPN holes, double extortion, Windows .ENCRT and Linux .GNRA. Affiliates advertised an 80% cut. Patch internet-facing VPNs and keep offline backups.

VUNVAULT News Desk · 10 Aug 2026 · 6 min read · sourced reporting
Joint #StopRansomware coverage. Advisory: CISA AA26-222A, 10 August 2026.

On 10 August 2026 the FBI, CISA, DC3, NSA, U.S. Secret Service and South Korea’s National Police Agency published #StopRansomware: Gunra (AA26-222A). Gunra appeared in April 2025 on leaked Conti source, then became a RaaS with a panel, Windows and Linux lockers, and recruitment of access brokers. Affiliates were offered as much as 80 percent of the ransom. Alias: Golden Community.

An 80 percent cut is the whole business model in one number. The developers keep a minority share, push a panel and two lockers, and let affiliates and access brokers do the hunting. Conti’s leaked source lowered the cost of standing up a brand. Gunra is what that leak continues to cost everyone else. You do not need a new criminal genius. You need a VPN that still has a 2024 CVE and a night shift that does not watch logs.

Joint #StopRansomware advisories are how the US and partners say a crew has graduated from rumour to doctrine. AA26-222A is long because the tradecraft is long. Read it as a playbook you can hunt, not as a press release you can file.

How they get in

Initial access is known holes on internet-facing firewalls and SSL-VPNs, including Fortinet CVE-2024-55591 and CVE-2025-24472, plus default VPN credentials when lockout is off. That last item is embarrassing and still real. A default admin on a VPN with no lockout is not a sophisticated intrusion. It is an unlocked door with a vendor sticker.

South Korea’s National Police Agency watched actors sniff SSL-VPN traffic, steal VDI cookies, dump NTDS with Impacket, and rewrite a VDI portal so a chosen OTP always worked — a standing MFA bypass. Sit with that. MFA was on. The portal was taught to accept a magic OTP. Every dashboard that said “MFA compliant” was telling a lie the attacker had engineered. Cookie theft from VDI means a stolen session is as good as a password. Dumping NTDS means the domain is next. This is not smash-and-grab encryption in the first hour. It is quiet access, then theft, then encryption.

Steal first, encrypt second, burn the backups

They steal first (OneDrive/SharePoint via a malicious main.exe; Mega via 7-Zip, RClone, FileZilla; tens of terabytes in at least one case), then encrypt. Double extortion is the default. Notes go in every directory; negotiation is Tor and qTox; the leak clock is five to seven days. They have deleted backups in both the primary and DR site. If your disaster-recovery plan is “the other datacentre,” and that datacentre is on the same domain with the same credentials, you do not have DR. You have a second copy for them to delete.

Windows files get .ENCRT (ChaCha20 + RSA-4096). Linux gets .GNRA; some Linux files may be recoverable if timestamps survive. That last clause is a small mercy and not a strategy. Do not plan on forensic luck. Plan on copies the domain admin cannot see, let alone delete. Immutable, offline, tested. The advisory is explicit because too many victims learned it in negotiation.

Tens of terabytes via everyday tools is the exfil lesson. RClone, FileZilla, 7-Zip, Mega, a binary named main.exe talking to Microsoft cloud. Your DLP and your firewall should already hate large outbound archives to file-share hosts at 3 a.m. If they do not, Gunra will not be the first crew to notice.

Who should feel named even if they are not

The advisory is written in American and Korean incident language. The kit is global. African hospitals and SACCOs run the same Fortinet boxes. Universities run the same SSL-VPNs. A Nairobi affiliate is optional. Mass scanners plus a broker who already sold a session are enough. Check Point’s July spike — 964 published ransomware victims, up 49% month-on-month — is the market Gunra lives in. Interpol’s Kenya chapter is the local hole set. AA26-222A is the named crew that will use both.

If you are a hospital, a SACCO, a county, a bank, or a BPO with a Fortinet or SSL-VPN on the internet, you are in scope. If lockout is off and a default admin still exists, you are not “at risk.” You are misconfigured.

Do this, in order

Patch VPN and firewall KEV items, including the Fortinet CVEs in the advisory, this week — not after the next board. Kill default admins. Turn lockout on. Take management interfaces off the public internet. Reset and monitor VPN sessions; stolen cookies mean a password change is not enough. Hunt for RClone, unexpected 7-Zip, FileZilla to Mega, and odd SharePoint or OneDrive batches. Segment so a popped VPN is not the whole domain. Watch the night shift; that is when the archives move.

Build backups the domain cannot reach. Test a restore. If you have never restored, you have a hope, not a backup. Pre-negotiate who calls law enforcement, who talks to regulators, and who does not talk to the affiliate on qTox without counsel. Paying is a business decision with no guarantee. Patching is a technical one with a better record.

Gunra does not need a Nairobi affiliate if your SSL-VPN is still last year’s build. AA26-222A is dated 10 August 2026. The CVEs are older. The window between “known exploited” and “our hospital” is the window you still have. Close it.

What an 80 percent affiliate cut does to your weekend

High affiliate splits mean more hunters, not fewer. Access brokers will keep selling Fortinet and SSL-VPN footholds because the locker crew pays. Your night-shift analyst is competing with a market, not a lone wolf. Detection has to assume commodity tooling: Impacket, RClone, 7-Zip, FileZilla, Mega, a VDI cookie, a rewritten OTP page. None of that looks like a film-hacker. All of it looks like admin work at 2 a.m. Alert on admin work at 2 a.m.

Linux .GNRA and Windows .ENCRT should be in your EDR and file-share alerts as extension watches, with the usual care about false positives. More useful: alert on mass file-rename and on backup-store deletion. The advisory says they have wiped primary and DR. If your backup console is domain-joined, treat that console as a ransomware objective. Separate identity. Separate network. Require a second person for delete.

Share the Fortinet CVE pair with every operator you still have on WhatsApp, including the hospital and the SACCO that will never open AA26-222A. Translate it: “If your VPN is on the internet and not patched for these two, turn it off until it is.” That sentence, sent today, is worth more than a printed copy of the joint advisory on a shelf. Gunra is a RaaS. Your unpatched SSL-VPN is the product they buy.

Print the extension names .ENCRT and .GNRA on the wall of the SOC next to the Fortinet CVE pair. When the first ticket arrives, you do not want a debate about spelling. Pair that with a simple executive line: this crew steals, then encrypts, then deletes DR. Paying after that sequence is buying a maybe. Patching the SSL-VPN is buying a smaller maybe. Choose the smaller one while it is still available.

← Back to the newsroom