Inside GentleKiller: The EDR-Killer Powering The Gentlemen

2026-06-20T20:51:42Z1d36ba722d60fc97463ed56992f0993453616aaefc712f346bbc5229d98d2d7f
24-billion-credentialsBYOVDCISACisco-ISEEDR-killerF5FortiBleedFortinetGentleKillerKnown Exploited VulnerabilitiesNGINXPeter-Thiel-leakSocGholishSplunkThe GentlemenWordPressclipper-malwarecredential-sprayingcredential-stuffingcrypto-theftincident-responsemass-data-leakransomwaretakedownvulnerability-patch

What happened

Multiple high-impact security events and vulnerabilities reported: a new EDR-killer toolkit (“GentleKiller”) used by The Gentlemen to disable security controls ahead of ransomware; FortiBleed — an industrial-scale credential-spraying operation that leaked credentials for ~74,000 Fortinet devices with active exploitation and a CISA alert; a global takedown of the SocGholish malware infrastructure and cleanup of ~15K WordPress sites; an exposed Elasticsearch collection of ~24 billion stolen credentials; clipboard-stealing (clipper) malware targeting crypto seed phrases; an information leak from:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1d36ba722d60fc97463ed56992f0993453616aaefc712f346bbc5229d98d2d7f
Enrichment time
2026-06-20T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.