TrendAI Research analyzed 200 Gemini CLI session logs from the Russian-speaking threat actor 'bandcampro,' revealing a solo operator who used Google Gemini CLI as the primary engineering agent to deploy and operate a C&C botnet targeting a dental clinic. The AI handled architecture design, coding, deployment, debugging, and WAF bypass autonomously, migrating the entire C&C infrastructure in six minutes. The operation is encoded in three portable plain-text files (~5KB) that can be shared and deployed by non-technical actors, representing a paradigm shift where AI lowers the skill barrier for complex cyber operations and makes infrastructure disposable and rapidly rebuildable.
VPN
14 posts
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet June 2026 Dark Web Breach Incident Trend Report The June 2026 Dark Web Breach Incident Trend Report summarizes major data breach cases observed on deep web and dark web forums. ShinyHunters claimed breaches across multiple sectors in North America and Europe, while Operation FortiBleed exposed large-scale credentials for security equipment and VPN accounts. The report also highlights emerging threats including AI-generated fake breach data, ransomware negotiation brokerage services on Russian-language forums, and potential manipulation of AI assistant platform response layers in the Middle East.
Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory FortiBleed is a severe, large-scale credential compromise campaign targeting internet-facing Fortinet FortiGate devices. Threat actors utilize a sophisticated pipeline, including the custom CyberStrike Harvester, to extract and crack credentials from device configurations and traffic captures, subsequently pivoting into internal networks for Active Directory enumeration and data exfiltration.
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways The NCSC has issued an alert regarding a global campaign targeting Fortinet firewalls and VPN gateways using brute-force and credential stuffing techniques. A threat actor has leaked a database of compromised credentials, prompting organizations to urgently check for exposure, investigate for unauthorized access or persistence, and perform factory resets on compromised devices.
Cyber Centre Daily Advisory Digest — 2026-06-18 (1 advisories) The Canadian Centre for Cyber Security issued an alert regarding 'FortiBleed,' a widespread campaign involving the leak of thousands of compromised credentials for Fortinet firewalls and VPN gateways. Threat actors can leverage these credentials, alongside vulnerabilities like CVE-2024-55591, CVE-2025-59718, and CVE-2025-59719, to gain remote access, create unauthorized accounts, and modify critical security controls.
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 Arctic Wolf Labs observed an ongoing campaign exploiting CVE-2026-0257, a high-severity authentication bypass vulnerability in Palo Alto Networks GlobalProtect. Threat actors are forging authentication override cookies to establish unauthorized VPN sessions, followed by rapid internal network reconnaissance using Impacket tooling.
Exposed RDP: The Misconfiguration that Keeps Paying Off Opportunistic threat actors continue to exploit exposed RDP, RDWeb, and vulnerable VPN configurations to gain initial access. Once inside, attackers deploy custom reverse tunnels, harvest credentials, and modify registry and firewall settings to establish persistent RDP access.
The State of Ransomware – Q1 2026 In Q1 2026, the ransomware ecosystem experienced significant consolidation, with top groups like Qilin, Akira, The Gentlemen, and LockBit 5.0 dominating the landscape. Notably, The Gentlemen leveraged a massive stockpile of pre-exploited FortiGate devices (CVE-2024-55591) to rapidly scale operations, while LockBit 5.0 returned with multi-platform capabilities and a strategic shift away from US targets to evade law enforcement.
Why Executive Accounts Are the Hardest Identity Problem to Solve Credential abuse via infostealer malware remains a primary initial access vector, with threat actors specifically targeting the accounts of executives and privileged users. By capturing authorization URLs alongside credentials, attackers can quickly identify and weaponize high-value access points, necessitating rapid detection and continuous monitoring of both corporate and personal VIP accounts.
M-Trends 2026: Data, Insights, and Strategies From the Frontlines Mandiant's M-Trends 2026 report highlights a severe divergence in adversary tactics. Cybercriminals are optimizing for speed, with initial access hand-offs collapsing to 22 seconds, and focusing on recovery denial by targeting hypervisors and backup infrastructure. Conversely, espionage groups are prioritizing extreme persistence by exploiting zero-days and deploying in-memory malware on unmonitored edge devices, while voice phishing has emerged as a primary vector for bypassing MFA and compromising SaaS environments.
2025 Identity Threat Landscape Report The 2025 Identity Threat Landscape Report highlights a massive surge in credential theft driven by infostealer malware, with LummaC2 leading the ecosystem. A critical finding is the widespread theft of active session cookies, which allows attackers to bypass multi-factor authentication (MFA) and directly access high-value corporate systems, VPNs, and cloud platforms.
“Handala Hack” – Unveiling Group’s Modus Operandi Handala Hack, an Iranian MOIS-affiliated threat actor also known as Void Manticore, conducts destructive wiping and hack-and-leak operations against US, Israeli, and Albanian targets. The group leverages compromised VPN credentials for initial access, uses NetBird for internal tunneling, and deploys multiple parallel wiping techniques—including custom MBR wipers, PowerShell scripts, and VeraCrypt—distributed via Active Directory Group Policy.
Preparing for Russia’s New Generation Warfare in Europe Over the next two years, Russia is expected to escalate its hybrid warfare against NATO into a coordinated New Generation Warfare (NGW) campaign. This strategy integrates cyber operations, physical sabotage, influence campaigns, and airspace/maritime incursions to degrade European critical infrastructure and political unity while remaining below the threshold of conventional armed conflict.