SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation

2026-04-22T01:24:12Z4b52d81b8199dd2fafcab2f2b175bbb91a54a5f9d7dcaf0158eefd4842f9453f
Anthropic-MCPApache-ActiveMQBRIDGE:BREAKCISA-KEVLantronixMiraiNGate-AndroidNexcoriumOT-malwareSGLangSilexSystemBCVercel-breachactive-exploitationbotnetidentity-attacksransomwareremote-code-executionserial-to-IP

What happened

Multiple high‑impact security stories: researchers uncovered a SystemBC C2 tied to The Gentlemen RaaS, revealing a botnet of >1,570 victims. Forescout disclosed BRIDGE:BREAK — 22 vulnerabilities affecting Lantronix and Silex serial‑to‑IP converters with ~20,000 exposed devices. Several critical RCEs and actively exploited flaws were reported, including SGLang CVE-2026-5760 (CVSS 9.8), Apache ActiveMQ CVE-2026-34197 (added to CISA KEV), and a Mirai variant (Nexcorium) exploiting CVE-2024-3721 to compromise TBK DVRs. Additional high‑risk findings include an Anthropic MCP design flaw enabling RCE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4b52d81b8199dd2fafcab2f2b175bbb91a54a5f9d7dcaf0158eefd4842f9453f
Enrichment time
2026-04-22T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.