CISA: Internet-exposed RDP remains the top ransomware entry point
In its 10 August 2026 Gunra ransomware advisory, CISA names internet-exposed RDP and VPN gateways as primary initial-access paths. ZoomEye counted 16.47 million RDP hosts on 28 September 2026, including 15.69 million on port 3389 and 3.35 million in the US.
- ZoomEye: 16.47M RDP hosts, 15.69M on port 3389
- US accounts for 3.35M exposed RDP hosts; VNC totals 9.19M
- Gunra exploited CVE-2024-55591 and CVE-2025-24472 in FortiOS and FortiProxy
- Advisory urges removing RDP from the internet, account lockout and offline backups
Read next
Security