Inside GentleKiller: The EDR-Killer Powering The Gentlemen
2026-06-21T08:51:48Z•71eb06e67bdb2d4805b874e757934f13b1c78e2ccf98a4238915e0328a566b5e
BYOVDCISACisco-ISEEDR-killerF5FortiBleedFortinetKnown-Exploited-VulnerabilityNGINXSocGholishSplunkThe Gentlemenclipper-malwarecredential-leakcredential-sprayingcryptocurrency-theftdata-breachlaw-enforcementpatchesransomware
What happened
Feed of high-impact security events: ESET analysis details 'GentleKiller,' an EDR-killer used by The Gentlemen to disable endpoint defenses ahead of ransomware via BYOVD techniques. FortiBleed exposed credentials for ~74,000 Fortinet devices and enabled active, large-scale credential-spraying/exploitation; CISA issued emergency guidance. CISA also added Splunk Enterprise vulnerability CVE-2026-20253 (CVSS 9.8) to its KEV catalog requiring urgent remediation. Law enforcement disrupted the SocGholish infrastructure and cleaned ~14,971 WordPress sites. A separate exposed Elasticsearch cluster and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 71eb06e67bdb2d4805b874e757934f13b1c78e2ccf98a4238915e0328a566b5e
- Enrichment time
- 2026-06-21T08:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.