Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation

2026-03-19T20:52:25Z359389f291a45b9137daa04509151952dc995c5007766320e0da5bc05109d761
AWS BedrockAppArmorCISA directiveCVE-2026-3888Cisco zero-dayCrackArmorDNS exfiltrationFortiGateHastalamuertePixRevolutionRaaSThe GentlemenVidar stealerinfostealerlaw enforcement takedownsmobile banking malwaren8n zero-clickprivilege escalationransomwarerapid exploitation

What happened

A wave of high-risk activity and multiple exploited vulnerabilities dominate recent reporting: ransomware affiliate leaks reveal The Gentlemen RaaS tradecraft (FortiGate exploits, BYOVD evasion, Qilin split tactics), while active exploitation of Cisco zero‑day(s) (called out by AWS and prompting a CISA emergency directive) and a critical zero‑click n8n flaw enabling full server compromise present immediate enterprise risk. Multiple privilege‑escalation issues (Ubuntu CVE-2026-3888, CrackArmor/AppArmor), an AWS Bedrock DNS exfiltration concern, and accelerating time‑to‑exploit trends compound a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
359389f291a45b9137daa04509151952dc995c5007766320e0da5bc05109d761
Enrichment time
2026-03-19T20:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation · Baitaphish