SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
2026-04-22T01:24:12Z•4b52d81b8199dd2fafcab2f2b175bbb91a54a5f9d7dcaf0158eefd4842f9453f
Anthropic-MCPApache-ActiveMQBRIDGE:BREAKCISA-KEVLantronixMiraiNGate-AndroidNexcoriumOT-malwareSGLangSilexSystemBCVercel-breachactive-exploitationbotnetidentity-attacksransomwareremote-code-executionserial-to-IP
What happened
Multiple high‑impact security stories: researchers uncovered a SystemBC C2 tied to The Gentlemen RaaS, revealing a botnet of >1,570 victims. Forescout disclosed BRIDGE:BREAK — 22 vulnerabilities affecting Lantronix and Silex serial‑to‑IP converters with ~20,000 exposed devices. Several critical RCEs and actively exploited flaws were reported, including SGLang CVE-2026-5760 (CVSS 9.8), Apache ActiveMQ CVE-2026-34197 (added to CISA KEV), and a Mirai variant (Nexcorium) exploiting CVE-2024-3721 to compromise TBK DVRs. Additional high‑risk findings include an Anthropic MCP design flaw enabling RCE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4b52d81b8199dd2fafcab2f2b175bbb91a54a5f9d7dcaf0158eefd4842f9453f
- Enrichment time
- 2026-04-22T01:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.