Cyware Daily Threat Intelligence - July 27, 2026

A wave of double-extortion ransomware is slashing through Europe and beyond, with The Gentlemen group clocking 144 attacks across Europe and the UK in the first half of 2026. Cyware.com tracks how this surge, fueled by exploitation of edge-device flaws, is forcing manufacturers, healthcare, and government organizations to confront both operational shutdowns and the threat of public data leaks.
Hundreds of organizations are exposed as attackers seize on unpatched Microsoft SharePoint servers, with 760 systems still vulnerable to remote takeover. Exploitation timelines show active abuse since June, as patch gaps persist in the US, the Netherlands, and beyond.
Phishing operations are evolving as BlueNoroff leverages fake Zoom and Teams meetings to target cryptocurrency holders. Deepfake video overlays, scripted chats, and malware that disables Microsoft Defender are turning routine invites into direct financial theft, with domains like googie[.]us-gmeet[.]com and hashes flagged for blocking.
Top Malware Reported in the Last 24 Hours
The Gentlemen ransomware spreads fast across regions
The Gentlemen ransomware group is a double-extortion operator that encrypts systems and steals sensitive data. The Gentlemen exfiltrate information before encryption, threatening public exposure even if victims restore from backups. The Gentlemen exploit known edge-device flaws, including Citrix NetScaler ADC (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591) to gain initial access. The Gentlemen target manufacturers, construction firms, healthcare providers, government bodies, and IT organizations. One analysis of Q2 2026 attributed 1,988 attacks by 89 active groups across 101 countries to this broader ransomware wave.
Hermes AI agent scouts Thailand ministry
The Hermes malware is an open-source autonomous AI agent used for cyber-espionage. Hermes autonomously explores networks, collects system details, and seeks elevated privileges, focusing on administrative web portals, email systems, and document management platforms. Hermes compresses reconnaissance and decision-making into a single workflow by leveraging automation. Hermes was deployed in an operation against Thailand’s Ministry of Finance, where exposed data included malware, stolen credentials, attack scripts, AI agent logs, and authentication cookies. Hunt[.]io discovered the campaign and identified a new backdoor family, Hades, with Windows and Linux variants capable of remote command execution and file transfer.
BlueNoroff weaponizes fake Zoom meetings
The BlueNoroff malware is a phishing kit linked to the Lazarus Group, designed to impersonate Zoom and Microsoft Teams. BlueNoroff uses reconnaissance techniques such as EIP-6963 provider discovery and legacy window.ethereum probing to identify high-value cryptocurrency targets. BlueNoroff deploys PowerShell loaders and VBScript implants to disable Microsoft Defender and perform system reconnaissance, while its macOS variant uses shell scripts and Mach-O binaries to steal credentials. BlueNoroff relies on deepfake-style video overlays and scripted chat to facilitate account takeover. The campaign’s guidance urges defenders to block known malicious domains and monitor for unauthorized access to cryptocurrency wallets and Telegram sessions.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-50522, CVE-2026-58644, and CVE-2026-56164: Unpatched SharePoint servers remain easy prey
The vulnerabilities CVE-2026-50522, CVE-2026-58644, and CVE-2026-56164 are remote code execution flaws in Microsoft SharePoint servers. Successful exploitation allows attackers to run malicious code, steal data, and seize control of affected systems. Attackers are actively exploiting these vulnerabilities in the wild, with exploitation timelines since June and July. The Shadowserver Foundation and the Netherlands’ National Cyber Security Centre (NCSC) have issued warnings about widespread abuse. Security updates were released in June and July, but 760 servers remain unpatched, including 331 in the United States and 25 in the Netherlands.
CVE-2026-61511: vBulletin bug lets strangers run code
The vulnerability CVE-2026-61511 is a pre-authentication remote code execution flaw in vBulletin forums. Successful exploitation allows any internet user to execute arbitrary PHP code, enabling data theft, defacement, or malware delivery. Attackers exploit the vB5_Template_Runtime::runMaths() method via the ajax/render/pagenav route and attacker-controlled input. The report notes that 20+ government sites have delivered malware to businesses and citizens through compromised platforms. A fix is available in vBulletin 6.2.2, and administrators are advised to review logs for suspicious requests.
SonicWall SMA zero-day hits remote access
A critical zero-day in SonicWall SMA 1000 series is rated CVSS 10.0 and allows attackers to execute arbitrary code. Successful exploitation can result in unauthorized access, data breaches, and service disruption. No evidence of active exploitation is provided, but the alert warns that attempts are likely due to the severity. The report highlights that SonicWall products are historically targeted because of their role in securing remote access. Patch availability is not specified; network segmentation and monitoring for unusual activity are recommended to reduce exposure.
Top Threat Actors Reported in Last 24 hours
BlueNoroff spoofs Zoom to steal crypto
The threat actor BlueNoroff (linked to the Lazarus Group), suspected to originate from North Korea, is financially motivated and targets cryptocurrency users. BlueNoroff uses a structured victim acquisition platform and social engineering, including deepfake video overlays and scripted chat, to harvest credentials. BlueNoroff deploys PowerShell loaders and VBScript implants on Windows to disable Microsoft Defender and perform reconnaissance, while on macOS, BlueNoroff uses shell scripts and Mach-O binaries with LLVM-based obfuscation to extract Keychain credentials and exfiltrate them via Telegram bot infrastructure. BlueNoroff targets high-value cryptocurrency holders and businesses managing digital assets. BlueNoroff’s recent campaign leverages fake Zoom and Microsoft Teams meetings as the access vector. Domains referenced for blocking include googie[.]us-gmeet[.]com, zoom[.]05ukweb[.]uk, weekly-up[.]online, and callsdk[.]online. Hashes referenced for blocking include 7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8d, 180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412f, 8889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775, a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2, 26bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28, and 163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683.
The Gentlemen ransomware scales global double-extortion
The threat actor The Gentlemen, suspected to be financially motivated, has rapidly expanded global operations using double extortion. The Gentlemen conduct fast-moving intrusions and exfiltrate data before encrypting systems, leveraging the RaaS ecosystem for scale. The Gentlemen exploit known vulnerabilities such as Citrix NetScaler ADC (CVE-2025-5777), SonicWall SSL VPN (CVE-2024-40766), and Fortinet FortiOS (CVE-2024-55591). The Gentlemen target Manufacturing, Construction, Healthcare, Government, and IT sectors. The Gentlemen’s campaigns are part of a broader ransomware trend, with 1,988 EDR-kill attacks by 89 groups across 101 countries in Q2 2026, and some crews deploy ransomware within an hour of initial access.
ShinyHunters claims massive DentaQuest data theft
The threat actor ShinyHunters, suspected to be an extortion-focused data theft group, is motivated by financial gain. ShinyHunters use unauthorized access to steal sensitive personal and dental health information, including Social Security numbers and government IDs. ShinyHunters claimed to have leaked 234 GB of data from DentaQuest, affecting at least 15 million individuals. ShinyHunters targeted patients and members of DentaQuest, exposing them to long-term identity and fraud risk. The campaign involved unauthorized access between May 17 and May 20, with notification letters sent to at least 4.5 million people. DentaQuest is offering affected individuals 24 months of free credit monitoring, fraud consultation, and identity theft restoration services.
Frequently Asked Questions
What is The Gentlemen? The Gentlemen ransomware group surged in the first half of 2026, racking up 144 attacks across Europe and the UK as it expanded across multiple regions. It uses double extortion, meaning it steals sensitive data before encrypting systems, so victims face the threat of exposure even if they can restore from backups.
What is Hermes? Hermes, an open-source autonomous AI agent, was used in a cyber-espionage operation against Thailand’s Ministry of Finance after researchers found a hacker-controlled server exposing the campaign’s internal files. It autonomously explored the network, collected system details, and looked for ways to gain elevated privileges while zeroing in on administrative web portals, email systems, and document management platforms.
What is BlueNoroff? BlueNoroff, linked to the Lazarus Group, built a phishing kit that impersonates meeting platforms like Zoom and Microsoft Teams to lure high-value cryptocurrency targets into handing over access. It uses reconnaissance techniques such as EIP-6963 provider discovery and legacy window.ethereum probing to identify which victims appear most valuable before pushing the next stage.
What is CVE-2026-50522? Hundreds of Microsoft SharePoint servers remain exposed to remote takeover through three security flaws—CVE-2026-50522, CVE-2026-58644, and CVE-2026-56164—that can let attackers run malicious code, steal sensitive data, and seize control of systems. The problem is lingering patch gaps: 760 servers are reported unpatched, including 331 in the United States and 25 in the Netherlands.
What is CVE-2026-61511? A pre-authentication remote code execution flaw in vBulletin (CVE-2026-61511) can let anyone on the internet execute arbitrary PHP code on vulnerable forums—turning a public website into an entry point for data theft, defacement, or malware delivery. The exploit path centers on the vB5_Template_Runtime::runMaths() method, where attacker-controlled input (such as the pagenav[pagenumber] parameter) can be pushed into a template math expression and ultimately executed.
What is ShinyHunters? ShinyHunters, an extortion-focused data theft group, has claimed responsibility for a breach at dental benefits provider DentaQuest that the company says could affect over 23 million people. They allegedly stole sensitive personal and dental health information during unauthorized access between May 17 and May 20, and claimed to have leaked about 234 GB of data.