Inside GentleKiller: The EDR-Killer Powering The Gentlemen

2026-06-21T08:51:48Z71eb06e67bdb2d4805b874e757934f13b1c78e2ccf98a4238915e0328a566b5e
BYOVDCISACisco-ISEEDR-killerF5FortiBleedFortinetKnown-Exploited-VulnerabilityNGINXSocGholishSplunkThe Gentlemenclipper-malwarecredential-leakcredential-sprayingcryptocurrency-theftdata-breachlaw-enforcementpatchesransomware

What happened

Feed of high-impact security events: ESET analysis details 'GentleKiller,' an EDR-killer used by The Gentlemen to disable endpoint defenses ahead of ransomware via BYOVD techniques. FortiBleed exposed credentials for ~74,000 Fortinet devices and enabled active, large-scale credential-spraying/exploitation; CISA issued emergency guidance. CISA also added Splunk Enterprise vulnerability CVE-2026-20253 (CVSS 9.8) to its KEV catalog requiring urgent remediation. Law enforcement disrupted the SocGholish infrastructure and cleaned ~14,971 WordPress sites. A separate exposed Elasticsearch cluster and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
71eb06e67bdb2d4805b874e757934f13b1c78e2ccf98a4238915e0328a566b5e
Enrichment time
2026-06-21T08:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Inside GentleKiller: The EDR-Killer Powering The Gentlemen · Baitaphish