Inside GentleKiller: The EDR-Killer Powering The Gentlemen
2026-06-20T20:51:42Z•1d36ba722d60fc97463ed56992f0993453616aaefc712f346bbc5229d98d2d7f
24-billion-credentialsBYOVDCISACisco-ISEEDR-killerF5FortiBleedFortinetGentleKillerKnown Exploited VulnerabilitiesNGINXPeter-Thiel-leakSocGholishSplunkThe GentlemenWordPressclipper-malwarecredential-sprayingcredential-stuffingcrypto-theftincident-responsemass-data-leakransomwaretakedownvulnerability-patch
What happened
Multiple high-impact security events and vulnerabilities reported: a new EDR-killer toolkit (“GentleKiller”) used by The Gentlemen to disable security controls ahead of ransomware; FortiBleed — an industrial-scale credential-spraying operation that leaked credentials for ~74,000 Fortinet devices with active exploitation and a CISA alert; a global takedown of the SocGholish malware infrastructure and cleanup of ~15K WordPress sites; an exposed Elasticsearch collection of ~24 billion stolen credentials; clipboard-stealing (clipper) malware targeting crypto seed phrases; an information leak from:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1d36ba722d60fc97463ed56992f0993453616aaefc712f346bbc5229d98d2d7f
- Enrichment time
- 2026-06-20T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.